Dehradun: Uttarakhand’s State Data Centre, operated by the Information Technology Development Agency (ITDA), has suffered another major cyberattack, disrupting more than 20 government websites and online services for nearly 15 hours. Officials said the attack was detected late Friday night, prompting authorities to immediately shut down the affected servers to prevent the suspected malware from spreading across the state’s digital infrastructure. Preliminary findings indicate that the attack may have involved a Russian malware variant. While all affected services have now been restored, cyber experts continue to conduct a detailed forensic investigation to determine the extent of the damage and identify the source of the intrusion.
According to ITDA officials, cybersecurity monitoring systems detected unusual activity across parts of the State Data Centre late Friday. Initial technical analysis suggested that several servers had been compromised by malicious software. As a precautionary measure, engineers isolated and shut down the affected systems to contain the suspected infection before it could spread to additional government networks. The emergency response resulted in the temporary suspension of several critical digital services, affecting the functioning of multiple government departments until restoration efforts were completed.
Authorities said the first significant impact was observed on the Crime and Criminal Tracking Network and Systems (CCTNS) portal, a key police platform used for online First Information Report (FIR) registration, criminal record management, and other law enforcement services. Shortly afterward, several other government websites also experienced technical disruptions. Officials stressed that, based on preliminary assessments, there is no confirmed evidence of sensitive data theft or permanent data loss. However, they cautioned that the final assessment will only be possible after a comprehensive digital forensic examination is completed.
ITDA Director Alok Kumar Pandey said the initial investigation indicates that the incident appears to be a Russian malware attack. He explained that once suspicious activity was detected, the technical team immediately activated emergency cybersecurity protocols and took the affected servers offline. Specialists then isolated the compromised systems and initiated malware containment and recovery procedures. By Saturday evening, normal operations had been restored and all affected government websites were brought back online in a phased manner. Officials added that services are currently functioning normally, while efforts to identify the malware’s origin and assess any operational or financial impact continue.
This is not the first time Uttarakhand’s State Data Centre has been targeted by a cyberattack. On October 4, 2024, the facility was hit by a major malware and ransomware attack that temporarily disrupted the Chief Minister’s Helpline, the e-Office platform, and more than 180 government websites. Earlier this year, another cyber incident forced the shutdown of over 10 government portals. The repeated attacks have raised concerns about the resilience of the state’s digital infrastructure and the growing sophistication of cyber threats targeting public-sector information systems.
According to renowned cybercrime expert and former IPS officer Prof. Triveni Singh, malware attacks on government data centres pose risks far beyond temporary website outages. If not detected and contained quickly, such attacks can compromise critical government databases, disrupt essential citizen services, and threaten sensitive digital infrastructure. He emphasized the importance of strengthening cybersecurity through network segmentation, real-time threat monitoring, multi-layer endpoint protection, regular security audits, and secure offline backups. He also noted that rapidly isolating affected systems and initiating forensic investigations remain among the most effective strategies for limiting damage during large-scale cyber incidents.
ITDA, cybersecurity specialists, and other concerned agencies are continuing a detailed technical investigation to determine how the attackers gained access to the network, whether any data was compromised, and whether the incident can be linked to an organised cybercrime group or an overseas threat actor. Officials said additional security measures are being implemented to strengthen the protection of Uttarakhand’s digital infrastructure and reduce the risk of similar attacks in the future. The findings of the forensic investigation are expected to guide further legal, technical, and administrative action.
About the author — Suvedita Nath is a science student with a growing interest in cybercrime and digital safety. She writes on online activity, cyber threats, and technology-driven risks. Her work focuses on clarity, accuracy, and public awareness.
