TechNewsReel
Live

Ransomware Gang Claims DRDO Breach; Defence Agency Denies Data Theft

A group calling itself Babuk Locker 2.0 announced a massive data leak in March 2025, though cybersecurity experts question the group's legitimacy and DRDO officials reject the allegations.

TechNewsReel Newsroom · July 27, 2026

A ransomware group claiming to be Babuk Locker 2.0 announced on March 10, 2025, that it breached India's Defence Research and Development Organisation (DRDO) and stole sensitive data, according to multiple independent news outlets including India Today, 63SATS, and VARIndia.

The group claimed to have exfiltrated 20 terabytes of data, though cybersecurity analysts suggest this figure is likely exaggerated. No independent source has confirmed an asking price for the alleged data, despite earlier reports citing an $8,000 figure.

DRDO Denies Breach

DRDO officials denied that the breached data belonged to their organisation. The agency has not provided detailed comment on the specific origins of the leaked files, leaving open whether any compromised data originated from DRDO systems or potentially from a former Defence Ministry official's personal device.

The exact size of any actually compromised data remains unverified, with claims ranging from a 753 MB sample to the full 20 TB announced by the ransomware group.

Analysts Question Group's Legitimacy

Cybersecurity analysts note that Babuk Locker 2.0 is likely a fake group using recycled LockBit 3.0 code. Security firms suggest the group's claims are exaggerated or fabricated, casting doubt on the scale and authenticity of the alleged breach.

Independent security researchers have not confirmed the legitimacy of Babuk Locker 2.0's claims.

Why It Matters

DRDO is India's primary agency for military research and development, responsible for critical strategic systems including missiles and aircraft. If verified, a breach of this magnitude at a top-tier defense agency could expose critical military secrets, research, and strategic capabilities to foreign adversaries or cybercriminals.

The incident underscores ongoing vulnerabilities in defence sector cybersecurity, even as questions remain about whether any DRDO systems were actually compromised.

Ongoing Uncertainty

Multiple outlets reported on the alleged breach with differing details, and the specific article originally citing the incident could not be independently located. Core elements of the story are confirmed by multiple independent sources, but key numerical details do not match across reporting.

Investigators continue to assess whether any data originated from DRDO systems and what information, if any, was actually compromised.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.