Episode 3: What Is Cyber Terrorism?
What Is Cyber Terrorism?
For research and classification purposes, cyber terrorism is defined more precisely as politically or ideologically motivated cyber activity conducted primarily by non-state or hybrid actors, designed to cause disruption of civilian infrastructure, public intimidation, or coercive political impact. This translates into four operationally applicable qualifying criteria. An incident is classified as a cyber terrorism candidate when it satisfies three or more of the following:
- Civilian sector targeting — the primary target is civilian infrastructure, public services, healthcare, financial systems, or democratic institutions rather than military systems.
- Public intimidation impact or demonstrated intent — the incident generates, or was evidently designed to generate, public fear, loss of confidence in essential services, or coercive political pressure.
- Identifiable political or ideological messaging — the actor profile, communication, or operational timing exhibits political or ideological motivation rather than purely financial motivation.
- Non-state or hybrid actor profile — the incident is attributed to, or consistent with attribution to, non-state actors, criminal collectives with ideological alignment, or hybrid actors operating with state toleration.
Terrorism, in classical terms, involves the deliberate use of violence or threat of violence against non-combatants to generate fear and coerce political outcomes. Cyber terrorism transposes this logic into the digital domain. The continuity lies in motive — political, ideological or religious coercion — and in the psychological objective of fear generation. The discontinuity lies in method: cyber terrorism employs network intrusion, disruption, manipulation or sabotage rather than physical explosives or firearms.
How Is It Different from Cyber Warfare?
Cyber warfare, by contrast, is state-directed activity organised by actor (state, proxy, coalition), objective (disruption, degradation, destruction, manipulation), strategic level (tactical, operational, strategic), legal threshold (below use of force, use of force, armed attack), domain integration, and temporal orientation. Establishing these structured categories enables precise empirical assessment of state cyber conduct and prevents conflation with terrorism, espionage or criminality.
The debate over whether cyber operations constitute "war" in the Clausewitzian sense remains unsettled. Clausewitz defined war as an act of force to compel an enemy to do one's will, and further as a continuation of policy by other means. Three core elements emerge from his framework: the organised use of force, political intent, and the dynamic interaction of opposing wills. The central difficulty in applying this to cyber operations lies in the concept of "force" — traditional war implies physical destruction and kinetic violence, whereas most contemporary cyber incidents fall below that threshold, functioning instead as espionage, sabotage or strategic signalling.
In the Indian context, cyber terrorism complicates this calculus. If extremist organisations employ cyber means to disrupt transportation systems, manipulate financial networks or incite communal violence with demonstrable casualties, the line between terrorism and cyber warfare narrows. When state sponsorship or facilitation is established, the act may acquire interstate war implications. Given India's nuclearised environment and the persistence of sub-conventional rivalry, cyber operations are more frequently employed as grey-zone instruments than escalatory war-fighting tools.
A recurring analytical challenge is the classification of state-sponsored actors targeting civilian infrastructure. The resolution adopted is definitional rather than operational: state actor profile leads to classification as cyber espionage/warfare, while non-state or hybrid actor profile leads to classification as a terrorism-candidate. Where actor attribution is unconfirmed — as in 54 percent of incidents in the comparable dataset — the incident is classified by the nature of targeting and impact rather than actor attribution.
Four mechanisms drive convergence between the two categories nonetheless. First, states use proxy non-state actors to achieve plausible deniability in attacks that meet the functional definition of cyber terrorism. Second, non-state groups exploit tools and vulnerabilities originally developed for state espionage campaigns as those tools are commoditised. Third, criminal syndicates with hybrid ideological-profit motivations blur the actor taxonomy. Fourth, both warfare and terrorism target identical digital infrastructure and exploit the same vulnerabilities in the CIA (confidentiality, integrity, availability) triad.
Cyber Terrorism in the Indian Context
In the Indian context, cyber terrorism has primarily manifested in three interrelated forms:
Cyber-enabled terrorism — the use of digital tools to support physical attacks, including recruitment, propaganda dissemination, encrypted communications, and financial transfers.
Cyber-dependent disruption — attacks targeting digital infrastructure directly, including defacement of government websites or distributed denial-of-service campaigns.
Information-psychological operations — disinformation, communal incitement and narrative warfare designed to amplify social fault lines.
Thus far, India has witnessed more cyber-enabled and psychological operations than large-scale destructive cyber terrorism targeting critical national infrastructure. This reflects both technical capability constraints among non-state actors and significant defensive improvements within India's critical sectors.
Recent trends indicate a convergence between traditional militancy and digital radicalisation ecosystems. Online propaganda, encrypted messaging platforms and cross-border digital influence operations have enhanced recruitment pipelines. The use of social media platforms for communal polarisation and mobilisation has created new vectors of instability, particularly during politically sensitive periods.
There has also been a notable increase in ransomware incidents affecting healthcare, energy and municipal services. While many such incidents are financially motivated and fall under cyber crime, the overlap between criminal syndicates and politically aligned proxies complicates classification. Attribution challenges make it difficult to distinguish purely criminal ransomware from strategically motivated disruption.
India's rapid digitalisation under national programmes has expanded the attack surface. The integration of digital identity systems, financial technology platforms and smart infrastructure creates efficiency gains but also systemic vulnerability. Consequently, resilience-building has become central to national security planning.
In the India–Pakistan dyad specifically, cyber activity functions as a grey-zone instrument — symbolic, deniable and calibrated — yet potentially destabilising if thresholds of infrastructure disruption or civilian harm were crossed. Informal hacker collectives frequently engage in website defacements and data leaks during periods of India–Pakistan tension. There are persistent allegations of proxy relationships between certain militant organisations and elements within Pakistan's security apparatus, raising the possibility of hybrid grey-zone operations where non-state actors conduct disruptive activities aligned with broader strategic signalling objectives.
Important Incidents and Case Studies
Mumbai electricity grid outage (October 2020) — The power failure that affected Mumbai in October 2020 was subsequently attributed by Recorded Future's Insikt Group to RedEcho, a Chinese state-linked threat actor, which had deployed ShadowPad malware across ten power-sector organisations and two major seaports. The campaign's strategic purpose appears to have been pre-positioning — establishing persistent access for potential activation during crisis conditions — rather than immediate disruption. Its inclusion as a terrorism-candidate case is significant because the targeted infrastructure — electricity supply to a civilian population of 12 million — meets the cyber terrorism definition on the target criterion even though the actor profile is state-linked.
Kudankulam Nuclear Plant malware (September 2019) — The DTRACK malware detection on the administrative network of the Kudankulam nuclear facility in Tamil Nadu was confirmed by the Nuclear Power Corporation of India Limited and traced to the Lazarus Group. The intrusion was limited to administrative systems; operational systems were stated to be air-gapped. Nevertheless, the incident demonstrated the willingness and capability of a state-linked actor to penetrate nuclear infrastructure — the highest-consequence category of critical infrastructure targeting.
Cosmos Bank cyber heist (August 2018) — The theft of approximately ₹94 crore (approximately USD 13 million) from Cosmos Cooperative Bank in Pune involved a coordinated malware attack on the bank's ATM switching system, enabling simultaneous withdrawals across 28 countries using cloned debit cards. The technical sophistication — simultaneous global execution, bypassing the core banking system — is operationally identical to techniques available to terrorist actors seeking to disrupt the financial system.
Angel One data breach (October 2024) — The exposure of 7.9 million user records through an AWS storage bucket misconfiguration at Angel One Securities triggered SEBI regulatory action, illustrating the structural vulnerability of India's rapidly expanding retail investment infrastructure to basic cloud security failures.
APT36 / Transparent Tribe (Pakistan-linked) — APT36 maintained persistent campaigns against Indian government, defence, education and diplomatic sectors throughout the study period, deploying spear-phishing, credential harvesting, the Android backdoor CapraRAT, Windows RATs including ElizaRAT, and the Linux implant Poseidon. The 2023–2024 expansion of targeting to include IITs and NITs confirms a strategic broadening from pure government/military intelligence collection to broader institutional reconnaissance.
AIIMS Delhi ransomware (November 2022) — The encryption of five AIIMS servers, affecting an estimated 4 crore (40 million) patient records, rendered patient management systems inaccessible for several weeks and forced a partial reversion to manual processes at one of India's premier public hospitals. The incident satisfies all four terrorism-candidate criteria and is the paradigmatic cyber terrorism case of the study period.
CoWIN database alleged breach (June 2023) — The reported exposure of citizen vaccination records for approximately 815 million Indians, alongside a separate ICMR COVID data leak in the same period, raised fundamental questions about the security of India's most sensitive public health data infrastructure. The scale of the potential exposure gives this incident a public fear and societal impact dimension that qualifies it as a terrorism-candidate regardless of whether the actor motivation was financial, political or ideological.
Information operations and disinformation — Election-themed phishing campaigns (January 2024), WhatsApp-propagated disinformation triggering localised communal incidents (2017–2023), and deepfake-enhanced social engineering attacks in the BFSI sector in H1 2024 collectively define a distinct attack category. These meet the public intimidation and political messaging criteria for terrorism even though they generate no system outages.
Key Takeaways
- Digitalisation is the dominant structural driver of incident growth. India's 37-fold increase in internet penetration — from 1.84% in 2011 to 68.19% in 2024 — is the single most powerful predictor of the 188-fold increase in reported cyber incidents over the same period (CAGR 49.6%).
- The election-period effect is directionally positive — a 5.6% higher expected incident rate in election months — though not yet statistically confirmed under current data structure.
- The sectoral targeting profile has shifted. Healthcare has emerged as the most targeted sector by malware detection volume (21.82% in 2024), with AIIMS and CoWIN/ICMR defining a new frontier of high-impact cyber terrorism.
- Most recorded "incidents" are pre-positioning, not terrorism. Network scanning and probing account for 88.8% of all CERT-In incidents by 2020 — systematic state-linked pre-positioning rather than ideologically motivated terrorism.
- Cyber terrorism in India remains primarily an enabling and amplifying mechanism, hybridising with digital radicalisation and cross-border narrative warfare rather than replacing conventional terrorism.
- The legal architecture is barely used. Section 66F of the IT Act, in force since 2008, has produced no publicly known standalone prosecution — most cases are pursued instead under the UAPA.
