New Delhi: In a major national security operation, the National Investigation Agency (NIA) on Monday executed simultaneous searches across five states in connection with a high-profile cyber-terrorism case involving coordinated Distributed Denial of Service (DDoS) attacks targeted at 54 Indian government websites and Critical Information Infrastructure (CII) during the cross-border military escalation known as Operation Sindoor. The federal probe aims to dismantle a sophisticated domestic and cross-border cyber syndicate accused of attempting to paralyze public digital portals and incite public panic during active border hostilities. For ongoing investigative reporting on national security and digital warfare, explore our national defense and crime desk portal.

Simultaneous Raids Across Five States

Operating on search warrants issued by a special NIA court, federal investigative teams searched five strategic locations spanning five states:

  • Maharashtra: Junnar in Pune district.
  • Gujarat: Nadiad in Kheda district.
  • Telangana: Ramagundam in Peddapalli / Karimnagar district.
  • Bihar: Gopalganj district.
  • National Capital: Designated locations across Delhi.

During the raids, investigators seized multiple digital devices—including three laptops, five smartphones, storage drives, and incriminating documentation detailing botnet leases, server proxy networks, and advanced hacking tutorials.

The Anatomy of the DDoS Attack on 54 Government Portals

The case originated from an initial First Information Report (FIR) registered by the Gujarat Anti-Terrorism Squad (ATS) on June 25, 2025, which was subsequently re-registered and taken over by the NIA (RC-01/2025/NIA/AMD). Two primary conspirators had been arrested earlier in the investigation.

According to federal cyber sleuths and technical intelligence reports from the Indian Cyber Crime Coordination Centre (I4C), the accused launched automated traffic surges to overwhelm and disable critical computing resources, ministerial domains, and public infrastructure portals precisely during the execution of Operation Sindoor in May 2025. The cyber offensive was coordinated with foreign-based threat groups and non-state hacker collectives to breach state sovereignty and compromise real-time defense communication systems.

Support Networks and Technical Handlers Under Scrutiny

Through deep digital forensics and server traffic tracebacks, the NIA identified intermediate suspects who provided critical logistical support, computational infrastructure, server-leasing channels, and technical skill upgrades to the operational hackers. Several individuals were detained for intensive questioning regarding financial transactions, cryptocurrency fund transfers, and their operational links to the arrested accused currently in judicial custody.

The agency noted that the multi-state crackdown forms part of a broader systemic effort to fortify India's national cyber perimeter against state-backed threat actors targeting civilian utilities, power grids, and critical governmental networks.