
The nameplate on the desk reads Sharma Enterprises. The laptop screen is blood red, with a skull icon above the words YOUR FILES HAVE BEEN ENCRYPTED, a demand for 0.05 BTC within 48 hours, and a countdown clock ticking down from 47 hours. This is not a hypothetical. It is the exact shape of a ransomware India 2026 incident, and small and mid-sized businesses are now squarely in the blast radius alongside the hospitals and government offices that used to dominate the headlines.
Ransomware detections on Indian small and medium businesses rose from 3.18 percent of all threats in Q1 2025 to 4.07 percent in Q1 2026, according to Kaspersky, across a base of more than 6.33 crore Indian SMEs. Healthcare providers fared worse still: attacks on Indian hospitals and clinics jumped roughly 700 percent between the second half of 2025 and the first half of 2026. None of this requires panic. It requires knowing exactly how these attacks unfold, why paying the ransom is almost always the wrong call, and the specific, free steps CERT-In and international responders recommend if it happens to you.
This guide covers how ransomware actually gets in, who is being hit in India right now with sourced cases, the data on why payment usually fails, and the protection and response checklist every business and phone owner should have ready before an attack, not after.
If a screen like this is in front of you right now
- 1Disconnect the device from Wi-Fi, ethernet and any shared drive immediately
- 2Do not turn the computer off, this can destroy recovery options held in memory
- 3Do not pay the ransom
- 4Report the incident to CERT-In at cert-in.org.in
- 5Check nomoreransom.org for a free decryption tool for your ransomware family
- 6Call a cybersecurity professional before doing anything else on that machine
Ransomware in India in 2026: A Growing Crisis
CERT-In, India's national cyber incident response agency, handled around 29.44 lakh cyber incidents in 2025 alone, issuing 1,530 alerts, 390 vulnerability notes and 65 advisories over the year. Ransomware sits at the sharper end of that caseload. Reported ransomware attack India activity surged more than 31 percent above the prior nine-month average in January 2026, and healthcare, one of the sectors CERT-In tracks most closely, absorbed an average of 2.3 ransomware attacks every single day during the first half of 2026, up nearly 14 percent from the second half of 2025.
The attacker playbook has also shifted. Newer ransomware groups such as Sinobi, which emerged in mid-2025 as a rebrand of the earlier Lynx and INC ransomware families, specifically target IT service providers and managed service companies for the supply chain multiplier effect: breach one vendor, and every one of its client organisations becomes reachable. In January 2026, Sinobi claimed an attack on an India-based IT services firm, alleging access to Hyper-V servers, virtual machines and customer backups, with more than 150 GB of contracts, financial records and customer data reportedly stolen.
Smaller cities are not being spared either. According to SARO's India Cybersecurity Threat Landscape 2025 to 2026 report, Tier 2 and Tier 3 city government offices are increasingly targeted precisely because they carry weaker cybersecurity budgets, no dedicated security operations team, and outdated legacy systems, an easier target than a metro headquarters with an in-house IT security desk.
How Ransomware Attacks Work, Step by Step
Every ransomware incident, from a single laptop to a hospital network, follows roughly the same four stages.
Step 1: The Entry Point, How Ransomware Gets In
An employee opens an email attachment, most often a PDF, Word document or ZIP file disguised as an invoice, delivery notice or HR communication, since phishing email remains the single most common entry point recorded in India. A malicious link shared over WhatsApp or email works the same way. Where a business exposes Remote Desktop Protocol (RDP) to the internet with a weak or reused password, attackers can simply log in directly, no phishing required. Infected USB drives round out the fourth major vector, still common in offices that allow external storage devices on work machines.
Step 2: Silent Spread, Before You Know Anything Is Wrong
Once inside, the malware typically does not encrypt anything right away. It quietly maps the network, looks for backup locations and shared drives, escalates its own access privileges, and in many modern ransomware cases, quietly copies sensitive files out to the attacker's own servers first. This is why the Sinobi attack on an Indian IT company reportedly reached Hyper-V servers, virtual machines and customer backups before anything was locked. This stage can last hours or weeks with no visible symptoms at all.
Step 3: Encryption, Files Locked, Ransom Note Appears
Once the attacker has positioned itself across as much of the network and as many backups as possible, the encryption routine runs, often within minutes, locking documents, databases and, in hospital cases, patient record systems. A ransom note replaces the desktop background or opens automatically, exactly like the skull screen and countdown shown above.
Step 4: The Demand, Bitcoin, Deadline, Threat to Publish
The note demands payment in cryptocurrency, almost always Bitcoin, within a fixed deadline, with a second threat layered on top in most modern attacks: publish or sell the stolen data if the deadline passes, even if the victim manages to restore files from a backup. This double extortion model is now the default for major ransomware groups, which is exactly why a backup alone, without also preventing data theft in the first place, is no longer a complete defence.

Who Is Being Attacked in India?
The pattern in India is consistent: attackers go after organisations holding critical data, running on lean IT security budgets, and facing intense pressure to restore operations fast, exactly the conditions that make paying a ransom look tempting.
Ransomware Hospital India: Healthcare Under Sustained Attack
- AIIMS Delhi, November 2022: the LockBit ransomware gang reportedly demanded around Rs 200 crore (roughly $24.5 million) after breaching one of India's largest government hospitals. Servers stayed down for six days, disrupting patient records and hospital operations nationwide.
- Sant Parmanand Hospital and NKS Super Speciality Hospital, Delhi, 10 to 11 June 2025: both hospitals reported an overnight server intrusion that disrupted IT systems. NKS confirmed OPD and IPD digital workflows had to revert to manual, paper-based processes. Delhi Police filed an FIR and cybersecurity experts were brought in to investigate.
- Sector-wide data: the Data Security Council of India's Cyber Threat Report found healthcare accounted for close to 22 percent of all attacks in India, up 8 percentage points from 2023, and Comparitech's H1 2026 healthcare ransomware roundup recorded 410 tracked attacks in the first half of 2026 alone, 247 of them against hospitals and direct-care providers.
Ransomware SME India 2026: Small Businesses Are Not Too Small to Target
- Bengaluru, private firm: attackers demanded $80,000, roughly Rs 66.7 lakh, threatening to sell the company's data on the dark web if it was not paid, according to Deccan Herald's reporting on the incident.
- Sector-wide SME data: Kaspersky recorded the share of ransomware detections among Indian SMBs rising from 3.18 percent in Q1 2025 to 4.07 percent in Q1 2026, across a base of more than 6.33 crore Indian enterprises employing over 130 million people, a base that is increasingly wired into larger enterprise and global supply chains, and therefore more attractive as an entry point into bigger targets.
- Salarpuria Sattva Group: one of India's largest real estate developers appeared on a ransomware group's dark web leak site in 2025, illustrating that company size alone is no protection.
- Sinobi, IT services company, January 2026: as detailed above, the Sinobi ransomware group claimed theft of over 150 GB of contracts, financial data and customer records from an Indian IT services provider, the exact profile of attack that can cascade into every client that provider serves.
Tier 2 and Tier 3 Government Offices
Per SARO's 2025 to 2026 threat landscape report, ransomware syndicates are deliberately shifting toward Tier 2 and Tier 3 city government offices, where cybersecurity budgets, dedicated security operations teams and modern infrastructure all lag behind metro-level institutions, making these offices comparatively easier to breach and slower to detect an intrusion in progress.
Should you pay a ransomware demand in India?
No. Here is why:
- 1Payment does not guarantee recovery. Independent research has found that as many as 40 percent of organisations that pay still fail to recover all of their data, and one widely cited Ponemon study found only 13 percent of paying victims got their data back in full.
- 2Paying proves the target will pay, which frequently invites a second, larger demand or a fresh attack from the same or an affiliated group.
- 3You may be funding organised criminal infrastructure, a legal and reputational risk in its own right, separate from the data loss itself.
- 4CERT-In's own guidance is explicit: organisations are not encouraged to pay the ransom, since it does not guarantee files will be released, and paying only encourages attackers to run more of these campaigns.
- 5Free decryption tools already exist for more than 160 ransomware variants through the No More Ransom project, and CERT-In offers incident response support at no cost.
Instead: isolate the infected device from every network, report it to CERT-In at cert-in.org.in, call your cybersecurity provider, and check for a free decryption tool at nomoreransom.org before you consider anything else.
The Real Cost of Paying, in Numbers
Globally, the willingness to pay is actually falling: in 2025, 63 percent of ransomware victims refused to pay, up from 59 percent in 2024, while the share who did pay dropped to 37 percent from 41 percent a year earlier. The median ransom payment also fell, from about $2 million in 2024 to roughly $1 million in 2025, a sign that both victims and insurers are pushing back harder. None of that changes the core finding that should drive every decision: paying is not a reliable path back to your files, and Indian authorities, CERT-In included, recommend against it every time.
How to Protect Your Business or Phone from Ransomware
Every one of the entry points described above has a specific, low-cost defence.
- Train employees to spot phishing. Since phishing email is the leading entry point in India, a five-minute quarterly refresher on suspicious attachments and links prevents more incidents than almost any single technical control.
- Patch and update everything. Operating systems, browsers and business software should update automatically wherever possible, since unpatched software is routinely exploited to install ransomware without any phishing step at all.
- Lock down or disable RDP. If Remote Desktop access is genuinely required, put it behind a VPN, enforce multi-factor authentication, and never leave it exposed directly to the internet on a weak or reused password.
- Restrict USB and external storage. Disable auto-run on removable drives and limit which devices can plug into business machines at all.
- Follow a ransomware backup strategy India businesses can actually maintain: the 3-2-1 rule. Keep three copies of your data, on two different types of media, with one copy stored fully offline and disconnected from any network. An offline backup is the one thing ransomware cannot reach and cannot encrypt.

What To Do If You Are Attacked Right Now
Speed and discipline matter more than technical skill in the first hour after discovery.

- Do not pay the ransom. It rarely guarantees recovery and can invite further extortion.
- Do not turn off the computer. This can destroy encryption keys or forensic evidence still held in memory that a responder could otherwise use.
- Do not connect backup drives to the infected machine. Ransomware actively hunts for connected backup media and will encrypt it too.
- Do not keep using the infected system. Every additional action risks spreading the infection further across the network.
- Disconnect from all networks immediately, Wi-Fi, ethernet, and any shared or mapped drive.
- Report to CERT-In at cert-in.org.in so the incident is logged with India's national response agency.
- Check free decryption tools at nomoreransom.org before assuming your files are unrecoverable.
- Call a cybersecurity professional to confirm the scope of the breach before reconnecting anything.
- Restore from a clean, offline backup if one is available, only after the infected systems have been fully isolated and cleaned.
30 Second Instagram Reel Script
Format: dark office lighting, quick cuts between the red ransom screen, the entry-point diagram, and the do or don't checklist card.
On-screen caption: Don't pay. Disconnect, report, restore.
Frequently Asked Questions
How does ransomware enter an Indian business network?
The most common entry points are phishing emails with malicious attachments, which remain the most common vector in India, malicious links sent over WhatsApp or email, Remote Desktop Protocol (RDP) exposed to the internet with a weak password, and infected USB drives. Keeping software updated and training employees to spot phishing are the two most effective preventions.
What should I do immediately if my computer is infected with ransomware in India?
Disconnect the infected computer from the network and the internet immediately. Do not turn it off, since this can destroy evidence and recovery options preserved in memory. Do not pay the ransom. Contact a cybersecurity professional, report the incident to CERT-In at cert-in.org.in, and check whether a free decryption tool already exists for your ransomware family at nomoreransom.org.
Is there free ransomware decryption help in India?
Yes. The No More Ransom project at nomoreransom.org, a joint initiative from Europol, the Dutch police and cybersecurity firms, offers free decryption tools covering more than 160 ransomware variants, built from keys recovered during law enforcement takedowns. In India, CERT-In at cert-in.org.in provides incident response support. Always check both before considering payment.
How can Indian SMEs protect themselves from ransomware?
The three most critical protections are maintaining offline or cloud backups that are never permanently connected to the main network, following the 3-2-1 backup rule, never opening email attachments from unknown senders, and keeping every operating system and application fully updated. Restricting Remote Desktop access and using strong, unique passwords closes two of the most common entry points used against Indian SMEs.
Are Indian hospitals and government offices targeted by ransomware?
Yes. Healthcare is one of the most frequently targeted sectors in India, accounting for close to a quarter of all recorded attacks, and Tier 2 and Tier 3 city government offices are increasingly hit because of weaker cybersecurity budgets and a lack of dedicated security teams. Attackers target organisations holding critical data with high pressure to restore operations quickly, since that pressure makes a ransom payment more likely.
Sources and Credits
- Comparitech, Healthcare Ransomware Roundup, H1 2026: 410 tracked healthcare attacks in H1 2026, 247 against hospitals and direct-care providers, 2.3 ransomware attacks per day, a roughly 700 percent rise in healthcare attacks between H2 2025 and H1 2026.
- Tripwire, Plagued by Cyberattacks: Indian Healthcare Sector in Critical Condition: Data Security Council of India Cyber Threat Report finding healthcare accounted for close to 22 percent of all attacks in India, up 8 points from 2023.
- Eventus Security, Top 15 Recent Cyber Attacks in India 2026: the Sant Parmanand and NKS Super Speciality Hospital, Delhi intrusion of 10 to 11 June 2025, and the Sinobi ransomware group's claimed attack on an India-based IT services company in January 2026.
- CM-Alliance, AIIMS Ransomware Attack: the LockBit ransomware attack on AIIMS Delhi, November 2022, the roughly Rs 200 crore ransom demand, and six days of server downtime.
- VarIndia, reporting Kaspersky data, Ransomware Detections Across Indian SMBs: the rise in ransomware detection share among Indian SMBs from 3.18 percent in Q1 2025 to 4.07 percent in Q1 2026, across India's 6.33 crore plus SME base.
- Deccan Herald, Ransomware Attack Hits Bengaluru Firm: the $80,000 ransom demand against a private Bengaluru firm and the threat to sell stolen data on the dark web.
- SOS Ransomware, Sinobi Ransomware, Successor to Lynx and INC: background on the Sinobi ransomware group and its origins as a rebrand of the Lynx and INC ransomware families.
- Vision IAS, CERT-In Handled Around 30 Lakh Cyber Incidents in 2025: CERT-In handling around 29.44 lakh cyber incidents in 2025, with 1,530 alerts, 390 vulnerability notes and 65 advisories issued.
- SARO, India Cybersecurity Threat Landscape 2025 to 2026: Tier 2 and Tier 3 city government offices increasingly targeted due to weaker cybersecurity budgets, no dedicated SOC teams, and outdated legacy systems.
- Business Standard, Giving in to Ransomware Threat: CERT-In's official guidance that organisations are not encouraged to pay a ransomware demand, since it does not guarantee release of files and encourages attackers to continue.
- The No More Ransom Project: the joint Europol, Dutch police and cybersecurity industry initiative offering free decryption tools for more than 160 ransomware variants.
- AAG IT Support, The Latest Ransomware Statistics: 63 percent of victims refusing to pay in 2025 versus 59 percent in 2024, and the median ransom payment falling from about $2 million in 2024 to roughly $1 million in 2025.
- CSO Online, Ransomware Recovery Perils: data showing up to 40 percent of organisations that pay a ransom still fail to fully recover their data.
- National Cybercrime Reporting Portal: the official complaint portal and India's national cybercrime helpline, 1930.
Verify the link before you open it
Most ransomware in India starts with one phishing email or one malicious link. Check a suspicious website, phone number or UPI ID on RakshaAI before you click, install or pay.
Check for freeMore from RakshaAI Blog
Stay Protected Online
Use RakshaAI to check websites, phone numbers, and UPI IDs for scams free, instant, no sign-up required.
RakshaAI is a private platform by Ehatech Services Pvt. Ltd. Not affiliated with any government body. Editorial policy


