Science & Technology·Revision Notes

Cyber Attacks — Revision Notes

Updated 10 Mar 2026

⚡ 30-Second Revision

  • Definition:Malicious digital acts to disrupt, disable, destroy, or control systems/data.
  • Key Types:Malware (Ransomware, Virus, Worm, Trojan), Phishing, DDoS, APT, Zero-Day, Supply-Chain.
  • Indian Legal Framework:IT Act 2000/2008, DPDPA 2023.
  • Key Bodies:CERT-In (Incident Response), NCIIPC (CII Protection).
  • Major Indian Incidents:2020 Mumbai Power Grid (disputed attribution), 2021 AIIMS Ransomware.
  • International Cases:Stuxnet (ICS), WannaCry (ransomware worm), NotPetya (wiper), SolarWinds (supply-chain).
  • Threat Actors:Nation-states, cybercriminals, hacktivists, insiders.
  • Impacts:Economic loss, national security risk, societal disruption.
  • Countermeasures:Technical (MFA, encryption, patching), Organizational (training, IR plans), Legal, Diplomatic.
  • Emerging Threats:AI-powered attacks, IoT vulnerabilities, Quantum computing concerns.

2-Minute Revision

Cyber attacks are malicious digital intrusions targeting systems and data, evolving from individual hacktivism to sophisticated state-sponsored warfare. Key attack types include malware (like ransomware, viruses, worms, and Trojans), phishing (social engineering via deceptive communications), Distributed Denial of Service (DDoS) attacks (overwhelming systems), Advanced Persistent Threats (APTs) (covert, long-term espionage), and supply-chain attacks (compromising trusted vendors).

These attacks are driven by diverse actors, from nation-states seeking geopolitical advantage to cybercriminals pursuing financial gain. The impacts are severe, encompassing economic losses, national security risks (especially to critical infrastructure), and societal disruption.

India's legal response is anchored in the IT Act 2000/2008 and the Digital Personal Data Protection Act 2023, supported by agencies like CERT-In for incident response and NCIIPC for Critical Information Infrastructure protection.

Major incidents like the 2020 Mumbai power grid event and the 2021 AIIMS ransomware attack highlight India's vulnerabilities. Countermeasures are multi-layered, involving technical safeguards (MFA, encryption), organizational policies (training, incident response), legal frameworks, and international cooperation.

Emerging threats, such as AI-powered attacks and IoT vulnerabilities, necessitate continuous adaptation and a proactive defense strategy.

5-Minute Revision

Cyber attacks represent a critical challenge in the digital age, defined as malicious attempts to disrupt, disable, destroy, or gain unauthorized access to computer systems and networks. Their evolution has been rapid, moving from early individual 'hacktivism' and financially motivated cybercrime to highly sophisticated, state-sponsored cyber warfare aimed at espionage, sabotage, and geopolitical influence. This shift necessitates a comprehensive understanding for UPSC aspirants.

Key Attack Vectors & Mechanisms:

  • Malware:Broad category including viruses (self-replicating, host-dependent), worms (self-propagating across networks), Trojans (disguised as legitimate software), spyware (data collection), and rootkits (covert access).
  • Ransomware:Encrypts data, demanding payment (often cryptocurrency) for decryption. Notable for its direct financial impact and operational paralysis.
  • Phishing/Social Engineering:Exploits human psychology to trick users into revealing sensitive information or executing malicious actions. Variants include spear phishing (targeted) and whaling (high-profile targets).
  • DDoS:Overwhelms a target with traffic from multiple sources (botnets), rendering services unavailable.
  • APTs:Long-term, covert, highly targeted attacks, often state-sponsored, focused on persistent access and data exfiltration.
  • Zero-Day Exploits:Leverage unknown software vulnerabilities, making them highly potent and difficult to detect.
  • Supply-Chain Attacks:Compromise a trusted vendor or software update to reach numerous downstream targets (e.g., SolarWinds).

Impacts:

  • Economic:Direct costs (recovery, fines), indirect costs (reputation, IP theft, business disruption).
  • National Security:Compromise of defense, intelligence, critical infrastructure (power, water, transport).
  • Societal:Privacy erosion, identity theft, disruption of essential services, loss of public trust.

India's Response:

  • Legal:Information Technology Act, 2000 (amended 2008) defines cyber crimes and penalties. Digital Personal Data Protection Act, 2023, mandates data breach reporting and safeguards privacy.
  • Institutional:CERT-In (Computer Emergency Response Team - India) is the national nodal agency for incident response. NCIIPC (National Critical Information Infrastructure Protection Centre) protects CII.
  • Policy:National Cyber Security Strategy 2020 (draft) aims for a secure cyberspace.
  • Incidents:2020 Mumbai power grid (suspected intrusion), 2021 AIIMS ransomware (healthcare disruption).

Countermeasures:

  • Technical:Firewalls, antivirus, MFA, encryption, regular patching, secure coding, network segmentation, robust backups.
  • Organizational:Strong cybersecurity policies, employee training, incident response plans, security audits, threat intelligence sharing.
  • Legal & Diplomatic:Enforcement of cyber laws, international cooperation, norms of responsible state behavior.

Emerging Threats: AI-powered attacks, IoT vulnerabilities, quantum-resilient cryptography, and escalating state-sponsored capabilities demand continuous vigilance and adaptive strategies.

Prelims Revision Notes

    1
  1. Cyber Attack Definition:Malicious attempts to disrupt, disable, destroy, or gain unauthorized access to computer systems, networks, or data.
  2. 2
  3. Malware Types:

* Virus: Attaches to legitimate programs, requires execution to spread. * Worm: Self-replicating, spreads autonomously across networks. * Trojan: Disguises as legitimate software, creates backdoors. * Ransomware: Encrypts data, demands ransom (e.g., WannaCry, NotPetya). * Spyware: Secretly monitors user activity. * Adware: Displays unwanted advertisements. * Rootkit: Hides presence, gains root-level access.

    1
  1. Phishing:Social engineering via deceptive emails/messages to steal info. Variants: Spear phishing (targeted), Whaling (high-profile), Smishing (SMS).
  2. 2
  3. DDoS (Distributed Denial of Service):Overwhelms a target with traffic from multiple sources (botnets) to cause unavailability.
  4. 3
  5. APT (Advanced Persistent Threat):Sophisticated, long-term, covert attacks, often state-sponsored, for espionage/data exfiltration.
  6. 4
  7. Zero-Day Exploit:Exploits unknown software vulnerability, no patch available.
  8. 5
  9. Supply-Chain Attack:Compromises a trusted vendor/software update (e.g., SolarWinds).
  10. 6
  11. SQL Injection (SQLi):Manipulates database queries via web app vulnerabilities.
  12. 7
  13. XSS (Cross-Site Scripting):Injects client-side scripts into web pages.
  14. 8
  15. Cryptojacking:Unauthorized use of victim's computer for cryptocurrency mining.
  16. 9
  17. Threat Actors:Nation-states, organized cybercrime, hacktivists, insiders.
  18. 10
  19. Indian Legal Framework:

* IT Act, 2000 (amended 2008): Primary law for cyber crimes. Sections 43 (damage), 66F (cyber terrorism). * Digital Personal Data Protection Act (DPDPA), 2023: Mandates data breach reporting, strengthens data privacy.

    1
  1. Indian Institutions:

* CERT-In: National nodal agency for cyber incident response. * NCIIPC: Protects Critical Information Infrastructure (CII).

    1
  1. National Cyber Security Strategy 2020 (Draft):Aims for secure cyberspace.
  2. 2
  3. Major Indian Incidents:2020 Mumbai power grid (suspected intrusion), 2021 AIIMS ransomware (healthcare disruption).
  4. 3
  5. International Cases:Stuxnet (Iran nuclear, ICS), WannaCry (global ransomware), NotPetya (wiper, Ukraine), SolarWinds (supply-chain, US govt).
  6. 4
  7. Countermeasures:Technical (MFA, encryption, firewalls, patching), Organizational (training, IR plans), Legal, Diplomatic.
  8. 5
  9. Emerging Threats:AI-powered attacks, IoT vulnerabilities, quantum computing, state-sponsored capabilities.

Mains Revision Notes

    1
  1. Introduction:Define cyber attacks, highlight their evolving nature from hacktivism to state-sponsored warfare, and underscore their multi-dimensional impact on national security, economy, and society.
  2. 2
  3. Evolving Threat Landscape:Discuss the shift from individual notoriety to organized cybercrime (financial gain, ransomware) and then to sophisticated state-sponsored attacks (espionage, sabotage, geopolitical influence). Use examples like Stuxnet, SolarWinds to illustrate.
  4. 3
  5. Key Attack Vectors & Technical Mechanisms:Detail the 'how' of attacks: ransomware's encryption lifecycle, supply-chain's vendor compromise, zero-day's exploitation of unknown flaws, and social engineering's human element. Emphasize their increasing sophistication.
  6. 4
  7. Impact Assessment:Analyze the economic costs (direct/indirect), national security implications (CII compromise, information warfare), and societal disruptions (privacy, essential services, trust erosion).
  8. 5
  9. India's Cyber Preparedness:

* Legal: IT Act 2000/2008 (provisions, penalties), DPDPA 2023 (data breach reporting, privacy). * Institutional: CERT-In (incident response, advisories), NCIIPC (CII protection, mandates). * Policy: National Cyber Security Strategy (objectives, implementation challenges). * Case Studies: Mumbai power grid (CII vulnerability, attribution challenge), AIIMS ransomware (healthcare impact, data recovery).

    1
  1. Challenges & Policy Gaps:Discuss issues like slow strategy implementation, skill shortages, lack of robust public-private threat intelligence sharing, difficulties in attribution, and the need for a clear cyber deterrence doctrine. Highlight the human factor as a persistent vulnerability.
  2. 2
  3. Comprehensive Countermeasures:Propose a multi-layered strategy:

* Technical: Advanced firewalls, EDR, SIEM, MFA, robust encryption, regular patching, secure coding, network segmentation, AI-driven detection. * Organizational: Strong cybersecurity policies, continuous employee training, well-defined incident response plans, regular audits, dedicated SOCs. * Legal & Diplomatic: Stronger enforcement, international cooperation, norms of responsible state behavior, capacity building.

    1
  1. Emerging Threats & Future Outlook:Address AI-powered attacks, IoT vulnerabilities, quantum computing challenges, and the escalating cyber arms race. Conclude with the imperative for a proactive, adaptive, and collaborative approach to secure India's digital future, linking to 'Digital India' and national resilience.

Vyyuha Quick Recall

Mnemonic

CIPHER: A Vyyuha Quick Recall for Cyber Attack Types

Flashcards

Letter

C

Concept

Confidentiality Attacks

Explanation

Attacks aimed at stealing or unauthorized access to sensitive information. Examples: Data breaches, espionage, identity theft. (e.g., APTs, Spyware)

Letter

I

Concept

Integrity Breaches

Explanation

Attacks that modify or corrupt data, compromising its accuracy or trustworthiness. Examples: SQL injection, data tampering, website defacement.

Letter

P

Concept

Phishing/Social Engineering

Explanation

Attacks that manipulate individuals into divulging information or performing actions through deception. Examples: Phishing emails, pretexting, baiting.

Letter

H

Concept

Hardware/Infrastructure Attacks

Explanation

Attacks targeting physical devices or critical operational systems. Examples: Stuxnet (ICS), supply-chain attacks (SolarWinds), IoT botnets.

Letter

E

Concept

Espionage/APTs

Explanation

Advanced Persistent Threats (APTs) focused on long-term, covert data exfiltration and intelligence gathering, often state-sponsored.

Letter

R

Concept

Ransomware/Financial Attacks

Explanation

Attacks demanding money, typically by encrypting data or disrupting services. Examples: Ransomware (WannaCry, NotPetya), cryptojacking, financial fraud.