iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› CERT-In: Cyber threats for fin, healthcare stay elevated

CERT-In: Cyber threats for fin, healthcare stay elevated

CERT-In data shared in Parliament shows cyber threat activity in India's finance and healthcare sectors stayed elevated in H1 2026, with detections crossing 60% of 2025 levels. Targeted bank campaigns fell to 17 from 39, while power-sector drills added a frontier AI scenario.

iG
iGEN Editorial
August 10, 2026
CERT-In: Cyber threats for fin, healthcare stay elevated

Cyber threat activity targeting India's finance and healthcare sectors remained elevated in the first half of 2026, with detections already crossing 60% of the levels recorded during the whole of last year, according to a Business Today report based on data shared by the government in Parliament. The figures, tracked through CERT-In detection and mitigation, provide a benchmark for enterprise security teams in two data-intensive industries.

Finance sector scanning volumes remain high

CERT-In detected and mitigated almost 3.5 lakh (350,000) instances of malicious scanning, probing and vulnerable services in the finance sector between January and June 2026, according to the report. This compares with 5.7 lakh instances during the whole of 2025.

Healthcare sector follows a similar curve

The healthcare sector recorded another 18,855 instances in the first six months of 2026, equivalent to nearly 55% of the 34,480 instances detected and mitigated during all of 2025, the report said. Together, finance and healthcare accounted for just under 3.7 lakh instances in the first half.

Together, finance and healthcare accounted for just under 3.7 lakh detected and mitigated cyber threat instances in the first half of 2026.

Targeted bank intrusion campaigns decline

However, the elevated scanning volume did not translate into a similar rise in targeted intrusion campaigns against banks. CERT-In detected and mitigated 17 such campaigns during January–June 2026, compared with 39 during the whole of 2025, according to the report.

Power-sector drills add frontier AI scenario

The report also detailed cybersecurity preparedness exercises for critical infrastructure. CERT-In conducted two exercises for the power sector in H1 2026, involving 274 participants from 103 organisations, including utilities, system operators and generation, transmission and distribution entities, according to the data.

One of those exercises focused on countering emerging cybersecurity risks posed by frontier AI models, indicating that threats linked to advanced AI systems are now being incorporated into preparedness drills for critical infrastructure. In comparison, CERT-In conducted three power-sector cybersecurity exercises during 2025, involving 150 participants from 30 organisations.

H1 2026 vs full-year 2025: CERT-In data at a glance

Metric Jan–Jun 2026 Full year 2025
Finance sector malicious scanning/probing instances almost 3.5 lakh 5.7 lakh
Healthcare sector instances 18,855 34,480
Targeted intrusion campaigns against banks 17 39
Power-sector cybersecurity exercises 2 3
Participants in power-sector exercises 274 from 103 organisations 150 from 30 organisations

What the figures mean for technology leaders

For CTOs, chief digital officers and security procurement leads across financial services, healthcare, and the power, logistics and trade technology providers that depend on these sectors, the CERT-In numbers quantify the threat environment: the combined finance and healthcare detection total for the first half of 2026 was just under 3.7 lakh instances, according to the report. The bank-campaign data shows that high scanning volumes do not necessarily mean more targeted intrusions.

The inclusion of a frontier AI threat scenario in a national power-sector exercise also shows that AI-related attack planning has entered official preparedness programmes, according to the report. The table above sets out the H1 2026 and full-year 2025 figures reported by CERT-In for comparison.


Sources: Business-Today

Keep Reading

Recommended Stories

CERT-In Mandates AI-Assisted Security Testing and Faster Patches for Technology Vendors in India Technology

CERT-In Mandates AI-Assisted Security Testing and Faster Patches for Technology Vendors in India

India's CERT-In has issued new cybersecurity guidelines requiring technology vendors to adopt AI-assisted security testing, disclose critical vulnerabilities immediately, and accelerate patch deployment. The framework also emphasizes supply-chain security, mandating detailed inventories of software, hardware, cryptographic tools, AI components, and third-party dependencies.

June 16, 2026
India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky Technology

India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky

India logged the most mobile threat detections among eight Asia-Pacific markets in Q1 2026, with 18,187 cases, ahead of Indonesia's 15,163. Kaspersky also reported a 49% year-on-year rise in average detections per affected user, alongside a resurgence of the Rewardsteal and Thamera trojans.

August 27, 2026
AI fraud hits India's new net users hardest, Amazon trust chief says Technology

AI fraud hits India's new net users hardest, Amazon trust chief says

Amazon's global trust and safety chief Rohan Oommen said AI-powered scams are a major threat to India's first-time online shoppers, whose lower awareness makes them especially vulnerable. Amazon's latest report shows the company removed nearly 300 million fake reviews and took down about 70,000 phishing websites globally last year.

August 4, 2026
Parliamentary Panel Summons Meta, X, Snapchat, and Google Over Online Safety Framework Technology

Parliamentary Panel Summons Meta, X, Snapchat, and Google Over Online Safety Framework

India's Parliamentary Standing Committee on Communications and Information Technology has summoned Meta, X, Snapchat, and Google to appear on August 3, 2026 to evaluate online safety and data privacy protections. The meeting follows the temporary removal of PM Modi's Facebook video and comes amid new anti-paper-leak legislation proposing tough penalties.

August 3, 2026