Cyber threat activity targeting India's finance and healthcare sectors remained elevated in the first half of 2026, with detections already crossing 60% of the levels recorded during the whole of last year, according to a Business Today report based on data shared by the government in Parliament. The figures, tracked through CERT-In detection and mitigation, provide a benchmark for enterprise security teams in two data-intensive industries.
Finance sector scanning volumes remain high
CERT-In detected and mitigated almost 3.5 lakh (350,000) instances of malicious scanning, probing and vulnerable services in the finance sector between January and June 2026, according to the report. This compares with 5.7 lakh instances during the whole of 2025.
Healthcare sector follows a similar curve
The healthcare sector recorded another 18,855 instances in the first six months of 2026, equivalent to nearly 55% of the 34,480 instances detected and mitigated during all of 2025, the report said. Together, finance and healthcare accounted for just under 3.7 lakh instances in the first half.
Together, finance and healthcare accounted for just under 3.7 lakh detected and mitigated cyber threat instances in the first half of 2026.
Targeted bank intrusion campaigns decline
However, the elevated scanning volume did not translate into a similar rise in targeted intrusion campaigns against banks. CERT-In detected and mitigated 17 such campaigns during January–June 2026, compared with 39 during the whole of 2025, according to the report.
Power-sector drills add frontier AI scenario
The report also detailed cybersecurity preparedness exercises for critical infrastructure. CERT-In conducted two exercises for the power sector in H1 2026, involving 274 participants from 103 organisations, including utilities, system operators and generation, transmission and distribution entities, according to the data.
One of those exercises focused on countering emerging cybersecurity risks posed by frontier AI models, indicating that threats linked to advanced AI systems are now being incorporated into preparedness drills for critical infrastructure. In comparison, CERT-In conducted three power-sector cybersecurity exercises during 2025, involving 150 participants from 30 organisations.
H1 2026 vs full-year 2025: CERT-In data at a glance
| Metric | Jan–Jun 2026 | Full year 2025 |
|---|---|---|
| Finance sector malicious scanning/probing instances | almost 3.5 lakh | 5.7 lakh |
| Healthcare sector instances | 18,855 | 34,480 |
| Targeted intrusion campaigns against banks | 17 | 39 |
| Power-sector cybersecurity exercises | 2 | 3 |
| Participants in power-sector exercises | 274 from 103 organisations | 150 from 30 organisations |
What the figures mean for technology leaders
For CTOs, chief digital officers and security procurement leads across financial services, healthcare, and the power, logistics and trade technology providers that depend on these sectors, the CERT-In numbers quantify the threat environment: the combined finance and healthcare detection total for the first half of 2026 was just under 3.7 lakh instances, according to the report. The bank-campaign data shows that high scanning volumes do not necessarily mean more targeted intrusions.
The inclusion of a frontier AI threat scenario in a national power-sector exercise also shows that AI-related attack planning has entered official preparedness programmes, according to the report. The table above sets out the H1 2026 and full-year 2025 figures reported by CERT-In for comparison.