Photo: analogicus / Pixabay
English
In February 2021 a US threat-intelligence firm said a China-linked group had targeted 10 Indian power-sector organisations, months after soldiers died in the Galwan valley. Maharashtra's government said a cyberattack may have caused Mumbai's October 2020 blackout, and the Union power minister said it was human error. A year later the same kind of activity turned up in grid control centres near Ladakh.
On Monday 12 October 2020, a little after 10 in the morning, the lights went out across Mumbai. A grid failure cut power to a city of about 20 million people and the suburbs around it, the first blackout of its kind there in more than two years, according to Gulf News. Suburban trains stopped on the tracks. Central Railway had its first services moving again at 10:55. The National Stock Exchange, the Bombay Stock Exchange and the international airport kept working, and Chief Minister Uddhav Thackeray ordered an immediate investigation and told officials to keep hospitals supplied, many of them treating Covid-19 patients. Tata Power said it had restored supply to the city by about noon.
The first explanations were ordinary ones. Early reports pointed to a “tripping at the Padgha-based load despatch centre in the Thane district,” as TechTarget later summarised them, and a load despatch centre is a control room that balances the supply of electricity against demand across an area. Gulf News reported the energy minister blaming “technical problems” during maintenance work.
Four and a half months later, on 28 February 2021, a US firm called Recorded Future dated a report titled “China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions.” Within days, ministers in Mumbai and Delhi were giving the public opposite answers about what it meant.
Ten targets and a backdoor
Recorded Future’s research arm, the Insikt Group, said it had identified 10 distinct Indian power-sector organisations as targets in what it called a concerted campaign. Four of them were Regional Load Despatch Centres, four of the five control rooms that run the national grid by region. Two were Indian seaports. The report named none of the victims.
The firm’s evidence was network traffic. It saw internet addresses belonging to Indian critical-infrastructure entities communicating over several months with a distinct set of servers used by the group it called RedEcho. Recorded Future said that pattern pointed to a targeted campaign, with little sign of wider targeting in its data. The servers were command servers for ShadowPad, a backdoor program, which is a hidden way into a computer that lets an attacker send it instructions. ShadowPad, the report said, “is used by at least 5 distinct Chinese groups.”
The firm did not pin RedEcho on any one of them. It found “strong infrastructure and victimology overlaps” (victimology means the pattern of who gets targeted) with two Chinese groups known as APT41, also called Barium, and Tonto Team. The Insikt Group said it did not believe there was enough evidence to attribute the activity to either one firmly. “China-linked” is therefore the firm’s own label.
The timing was part of the report’s case. On 15 June 2020, soldiers of the two armies had fought in the Galwan valley in Ladakh. The US-China Economic and Security Review Commission, a body set up by the US Congress, counts at least 20 Indian deaths and calls it the first time since 1975 that soldiers from either side had died on that border. Recorded Future saw a steep rise in the activity’s infrastructure from mid-2020 onwards.
Its assessment of the purpose reads as follows: “The targeting of Indian critical infrastructure offers limited economic espionage opportunities; however, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives.”
Pre-positioning means getting into a system and staying there so the access is ready if it is ever wanted. The report listed what it might be wanted for: “Pre-positioning on energy assets may support several potential outcomes, including geo-strategic signaling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation.” Recorded Future also said it notified the appropriate Indian government departments before publishing, so that the affected organisations could investigate.
What Recorded Future would not say
The report did not claim to have found the cause of the blackout. TechTarget quoted the firm’s position: “At this time we cannot confirm that the RedEcho activity group nor this campaign is linked to the power outages experienced in the Mumbai region in October 2020.”
Christopher Ahlberg, Recorded Future’s chief executive, was quoted in the same report. “The activity puts civilian critical infrastructure at risk and should not be done,” he said.
Newspapers in India and abroad put the two stories side by side within a day. The Quint’s account of the coverage records that Maharashtra’s government took note of the study and that its cyber department had submitted findings suggesting possible sabotage. Nitin Raut, the state’s energy minister, said Maharashtra had formed three committees to look into the outage, and told reporters he believed there was more to it than a technical glitch.
One detail is easy to miss. Business Today reported that the state cyber department had traced suspected malware to the Padgha-based state load despatch centre, the same place the first reports of the outage named. Padgha is a state centre. The centres in Recorded Future’s report were regional ones, and the report did not say which organisations they were.
Mumbai said sabotage, Delhi said human error
On 1 March 2021, Maharashtra’s Home Minister, Anil Deshmukh, told reporters that a preliminary report from the state’s Cyber Cell suggested the outage might have been cyber sabotage. As he described it, the report found 14 Trojan horses (programs that pose as harmless software) on the state power utility’s servers, 8 GB of data that may have been moved from an outside server onto them, and an attempted login from a blacklisted IP address. Deshmukh did not name a country.
In Delhi, the Union Power Minister, R.K. Singh, gave a different account within days. BOOM, the fact-checking site, reported his words. “Two teams investigated the power outage and reported that the outage was caused by human error and not due to cyber attack,” Singh said. He added: “One of the teams submitted that cyber attacks did happen but they were not linked to the Mumbai grid failure.” The Quint reported him saying that the government had no evidence that either China or Pakistan had carried out the attacks.
The Power Ministry also disclosed that the government had been warned about the same malware family. “An email was received from CERT-In on 19th November, 2020 on the threat of malware called Shadow Pad at some control centres of POSOCO,” the ministry said. CERT-In is the national computer emergency response team. POSOCO is the state-owned company that runs the grid control rooms. The date is about five weeks after the blackout and more than three months before the American report appeared.
China rejected the allegation. Its foreign ministry spokesman, Wang Wenbin, said on 1 March that it was irresponsible and ill-intentioned to make such accusations without proof, and that China firmly opposes cyberattacks of any kind.
Three positions now stood side by side. Maharashtra’s cyber department said sabotage might have happened. The Union Power Ministry said its two investigating teams found human error, with separate intrusions that did not cause the failure. Recorded Future said it could not confirm any link. We found no public document that traces the 12 October outage to a hostile actor, Chinese or otherwise, and no published copy of either team’s report.
Three claims and what backs them
Each of the three positions rests on a different kind of evidence. Maharashtra’s rests on its cyber department’s reading of material from the state utility’s own servers, passed to the public as a list of figures read out by a minister: 14 programs, 8 GB, one login attempt. The full Cyber Cell report did not appear in any of the coverage we reviewed.
The Union ministry’s position rests on two investigating teams, whose findings it summarised in a few sentences. One of those sentences concedes that cyber attacks happened. The part it denies is a causal link to the grid failure, which is a narrower claim than saying no intrusion took place.
Recorded Future’s rests on traffic seen from outside the networks. That kind of data shows which addresses talked to which servers, and for how long. The firm’s public statement about Mumbai is the single sentence quoted above, and Ahlberg’s remark about civilian infrastructure was addressed to the intrusions themselves.
Ladakh, 2022
On 6 April 2022, Recorded Future published a second report, this time on a group it called TAG-38 and described as a likely Chinese state-sponsored group. It said it had found at least seven State Load Despatch Centres in north India, near the disputed border in Ladakh, among the targets. The list also included India’s national emergency response system and the Indian subsidiary of a multinational logistics company.
The tool was ShadowPad again. This time the attackers ran their command channel through compromised DVRs and IP cameras, which are the boxes that store CCTV footage and the networked cameras that feed them. The report also described a tool called FastReverseProxy, which relays traffic through a compromised machine. Recorded Future wrote that “we have not identified technical evidence allowing us to attribute it to RedEcho.” It called the activity “pre-positioning for future activity.” The report did not claim that any outage had occurred.
R.K. Singh answered on Thursday 7 April, and this time he used the words “Chinese hackers” himself. “Two attempts by Chinese hackers were made to target electricity distribution centres near Ladakh but were not successful,” he said, as The Quint reported. He added: “We’ve already strengthened our defence system to counter such cyber attacks.”
The two accounts do not line up number for number. Recorded Future listed at least seven centres, and the minister counted two attempts. Its report concerned load despatch centres, the control rooms that balance supply and demand, while the minister spoke of distribution centres. The minister’s statement is on the record as a government acknowledgement of Chinese attempts near Ladakh, with a denial that they succeeded.
Aadhaar, a newspaper and a police force
The grid was one target among several. In September 2021, Bloomberg reported on a Recorded Future finding about another group, which the firm tracked as TAG-28 and which used a malware family called Winnti. Its victims included the Unique Identification Authority of India, which runs Aadhaar, the media company Bennett Coleman, and the Madhya Pradesh Police.
According to Bloomberg, about 500 megabytes of data left the media company between February and August. The police department lost about 5 megabytes. The UIDAI intrusion was smaller still, at about 10 megabytes downloaded and 30 uploaded. Recorded Future said it had seen a 261 percent rise in suspected state-sponsored Chinese operations against Indian organisations in 2021 so far, compared with the whole of 2020. Bloomberg noted that Chinese authorities have consistently denied involvement in state-sponsored hacking.
UIDAI’s reply was short. It said it had no knowledge of a “breach of the nature described.” Bloomberg’s account rests on Recorded Future’s findings, and the agency’s denial is the only official response it reports.
Banned apps, trusted vendors, certified cameras
India’s first answers to the border crisis did not wait for any grid report. On 29 June 2020, 14 days after Galwan, the government blocked 59 Chinese apps, TikTok among them, under Section 69A of the IT Act. The ministry said it had received reports of apps transmitting users’ data without authorisation to servers outside India, and that the apps were engaged in activities “prejudicial to sovereignty and integrity of India, defence of India, security of state and public order.”
In telecom, a Department of Telecommunications amendment to operators’ licences took effect on 15 June 2021. From that date operators could deploy only equipment from “Trusted Sources” that the National Cyber Security Coordinator had notified, and anything outside the list needed special permission. MediaNama noted that the change was widely understood as aimed at Chinese vendors such as Huawei and ZTE. Maintenance of equipment already installed was exempt.
The cameras came last. From 9 April 2025, all internet-connected CCTV equipment sold in India needs certification from the Standardisation Testing and Quality Certification directorate, known as STQC. The process can require a maker to hand over source code, accept a factory audit and have its devices tested in government labs. A senior official told Reuters that “China is part of the concern.” Xiaomi told the news agency that Indian labs had asked its China-based contract manufacturers for additional documents, citing “internal guidelines” for firms from countries that share a land border with India.
Hikvision and Dahua, two Chinese camera makers, are widely described as banned. That is not accurate. PTC News reported on 1 April 2026 that officials were withholding approvals from their devices and from devices using Chinese-origin chipsets, which stops the products being sold legally without any ban order. We found no formal order banning either company.
Still at it in 2026
On 28 June 2026, the Acronis Threat Research Unit attributed a new campaign against India to Mustang Panda, a Chinese group, with high confidence. Its basis was overlaps in tradecraft, in malware code and in server infrastructure with earlier Mustang Panda activity. The targets were India’s hydropower sector and government bodies that have cooperation agreements with Taiwan.
The bait was a pair of zip files with the names “Hydropower Cooperation Project Proposal.zip” and “MOU USI-INDSR TAIWAN.zip.” The malware Acronis named ZOHOMURK used Zoho WorkDrive, a cloud storage service from the Indian software company Zoho, to receive commands and move stolen data out. Acronis described the service as one commonly used in the Indian government, which makes the traffic look ordinary. A second implant, MINIRECON, derives from a malware family called Toneshell. Among the clues Acronis listed for its attribution were consistent misspellings in the code, including “RunOnece,” alongside code similarities to Mustang Panda tools documented earlier.
In May 2026, The Hacker News reported that Trend Micro had identified a cluster it called SHADOW-EARTH-053, active since at least December 2024. India was one of its targets, along with Pakistan, Thailand, Malaysia, Myanmar, Sri Lanka, Taiwan and Poland. The group got in through known flaws in internet-facing Microsoft Exchange and IIS servers and planted web shells, small programs that give an attacker remote control of a server, one of them called Godzilla. It then staged ShadowPad, the same backdoor Recorded Future found in India’s grid in 2021.
Telecom shows up in the record as well, with less certainty. In February 2025, Recorded Future reported that “more than half of the targeted Cisco devices were located in the U.S., South America and India” in a campaign by the group known as Salt Typhoon. Cybersecurity Dive’s account of that report names no Indian telecom company among the confirmed victims.
What India will not say
Almost everything above comes from foreign security firms, with ministers’ answers beside it. Recorded Future, Trend Micro and Acronis publish their findings. The Indian agency charged with protecting the country’s most sensitive systems has said it does not.
The National Critical Information Infrastructure Protection Centre, or NCIIPC, was created under Section 70A of the IT Act by a notification of 16 January 2014 and works under the National Technical Research Organisation. When Parliament asked about attacks on critical infrastructure, the government’s written reply relayed the agency’s position: that revealing details of cybersecurity breaches on critical infrastructure would not be in the interest of national security.
The same reply lists the machinery that does exist. CERT-In is designated under Section 70B of the Act as the national agency for responding to cybersecurity incidents. A National Cyber Security Coordinator sits in the National Security Council Secretariat, and a National Cyber Coordination Centre run by CERT-In serves as a control room that scans Indian cyberspace for threats. The reply also cites an allocation of ₹782 crore for cybersecurity projects in the Union Budget of 2025.
The reply was published by the Press Information Bureau on 26 March 2025.
Sources & further reading
- Recorded Future, Insikt Group: China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions (28 February 2021)
- TechTarget: Chinese threat group RedEcho targeting Indian power grid (1 March 2021)
- Scroll.in: Mumbai power outage, supply restored in most parts, Uddhav Thackeray orders investigation (12 October 2020)
- Gulf News: India's financial capital Mumbai hit by massive power outage (12 October 2020)
- Business Today: Cyber attack from China behind Mumbai power outage in 2020 (1 March 2021)
- Business Standard: Mumbai power outage may have been cyber sabotage, Anil Deshmukh (1 March 2021)
- The Quint: No Proof of Chinese Role in Mumbai Power Outage, Union Power Minister RK Singh (March 2021)
- The Quint: Did China Cause Power Cut in Mumbai? Here's What a Study Suggests (1 March 2021)
- BOOM: Mumbai Power Blackout, Was It A Cyberattack From China? (4 March 2021)
- US-China Economic and Security Review Commission: Conflict on the Sino-Indian Border, Background for Congress
- Recorded Future: Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group (6 April 2022)
- The Quint: Chinese hackers targeted Indian power grids near Ladakh, report (7 April 2022)
- Bloomberg via Yahoo News: Indian government, media company targeted by suspected Chinese hackers (September 2021)
- Business Standard: India bans 59 Chinese apps including TikTok, UC Browser and others (29 June 2020)
- MediaNama: DoT amends licences for trusted sources (10 March 2021)
- Business Today (Reuters): China part of concern, India's CCTV crackdown over spying fears hits global giants (28 May 2025)
- PTC News: India CCTV rules, Hikvision and Dahua, STQC (1 April 2026)
- Acronis Threat Research Unit: Mustang Panda targets India's government and energy sectors with ZOHOMURK and MINIRECON (28 June 2026)
- The Hacker News: China-linked hackers target Asian governments and a NATO member (1 May 2026)
- Cybersecurity Dive: China-backed hackers continue cyberattacks on telecom companies (13 February 2025)
- Press Information Bureau: Government Taking Measures to Strengthen National Preparedness Against Cybersecurity Threats (26 March 2025)
Researched and written with the help of AI tools and edited for accuracy. Provided for general information and discussion only, not professional advice. See our editorial standards and disclaimer. Spotted an error? Tell us.
Enjoyed this? Get the next one.
One good read at a time, straight to your inbox. No spam, unsubscribe anytime.