Verify any claim · lenz.io
Claim analyzed
Tech“A threat actor is offering for sale 31 GB of allegedly exfiltrated highly sensitive data belonging to the Defence Research and Development Organisation (DRDO) and the Indian military for USD 8,000.”
Submitted by Bright Heron 13c5
The conclusion
Open in workbench →Available reporting supports that a threat actor posted a dark-web sale offer for 31 GB of purported DRDO and Indian military data at USD 8,000. The strongest evidence is consistent on those specifics, and the claim is carefully limited to allegedly exfiltrated data rather than a confirmed breach. The main limitation is that reporting appears to rely on the same underlying listing, with no strong independent verification of the data's authenticity.
Caveats
- Low confidence conclusion.
- The evidence supports the existence of the sale listing more strongly than it supports that the data was genuinely exfiltrated from DRDO or military systems.
- Multiple reports appear to derive from the same underlying dark-web post, so source independence is limited.
- The description “highly sensitive” is based on reported sample contents and has not been independently verified from primary evidence.
Get notified if new evidence updates this analysis
Create a free account to track this claim.
Sources
Sources used in the analysis
India Today reported that the Babuk Locker 2.0 group said it had exfiltrated 20 terabytes of data from DRDO systems and publicly released a 753 MB sample. The article also says DRDO officials denied any breach of their organisation’s data and said the data did not belong to DRDO.
On July 11, 2026, a dark-web forum post reportedly offered 31 GB of sensitive data allegedly taken from the Defence Research and Development Organisation’s Research Centre Imarat (RCI) and the Indian military for $8,000. The post’s samples were described as missile seeker design documents, a military UAV capability matrix, and an SAAW integration plan.
A threat actor, identified by the tracker as Babuk, compromised India’s Defense Research and Development Organization for espionage purposes. The entry records the incident as discovered on March 11, 2025 and links it to DRDO data exposure.
Access to Indian Ministry of Defence and Military Secret (DRDO) documents by Babuk Locker 2.0. The listing states it was discovered on March 10, 2025 and concerns access to Indian Ministry of Defence and military secret documents.
A Chinese-language cyber threat report stated that on 2026-07-11 a hacker claimed to possess 31 GB of highly sensitive data allegedly stolen from DRDO and the Indian military and priced it at USD 8,000. The report said sample files included missile seeker designs, UAV capability matrices, and precision-guided munition integration documents.
The group initially demanded a ransom of $25,000 but quickly dropped the price to $5,000, an unusual move for ransomware operators dealing with high-value intelligence. The report also says some released documents appeared to be old files taken from an internet-connected machine belonging to a former Indian defence official.
BreachSense listed a Babuk-linked incident involving the Indian Ministry of Defence and DRDO, with the discovery date given as March 11, 2025 and the leak size listed as 20TB. This is secondary breach-intel reporting rather than an official confirmation.
RedPacketSecurity documents a ransomware incident titled "Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker," noting that the Babuk Locker group leaked sensitive information related to the Indian Ministry of Defence and DRDO. The post says the ransomware group gained unauthorized access to confidential military documents, raising national security concerns. It states that the post about the leak was made public on March 10, 2025, but does not specify the exact amount of data exfiltrated beyond describing it as sensitive Ministry of Defence and DRDO information.
The New Indian Express reported that DRDO’s Directorate of Public Interface said a fact-finding inquiry committee was formed, but the committee did not find evidence supporting the allegation of a security breach in the BrahMos-related complaint. This is relevant as a DRDO denial of a different alleged leak, showing the organisation’s public response pattern.
The Times of India reported an earlier defence breach in which hacked Defence Ministry and DRDO computers may have led to leaked information. The article said some classified military material may have been compromised when around 50 computers belonging to the armed forces and DRDO were hacked.
The DRDO espionage case involves allegations that a senior scientist, Pradeep Kurulkar, passed confidential information from the Defence Research and Development Organisation (DRDO) to a Pakistani intelligence operative. The Anti‑Terrorism Squad in Maharashtra is investigating whether sensitive DRDO technical data were exfiltrated and shared, highlighting ongoing concerns around insider threats and protection of India’s defence secrets. The case has been described as a serious security breach for India’s defence research establishment.
This case study describes a DRDO‑related data breach where a misconfigured public AWS S3 bucket belonging to Bharat Electronics Limited (BEL) exposed sensitive files associated with DRDO. The bucket was accessible from 2019 to 2021 and contained defence‑related documents, creating significant national security and compliance risks. The incident illustrates how third‑party or vendor cloud misconfigurations can result in unintentional exposure of sensitive DRDO data, distinct from deliberate exfiltration by external threat actors on dark‑web forums.
A report cites Indian security experts as saying that Chinese hackers breached systems of the Defence Research and Development Organisation (DRDO), leading to the leak of thousands of top secret files related to Cabinet Committee on Security matters. The stolen data, including documents related to surface‑to‑air missile and radar programmes from DRDO labs, were traced to a server in Guangdong province in China. The incident was described as one of the biggest security breaches in the Indian defence establishment at the time.
Around 50 computers belonging to the armed forces and the Defence Research and Development Organisation (DRDO) were hacked, and classified files may have been compromised, according to government sources. The affected systems were located in South Block and belonged mainly to the Army and other services, and security agencies feared that up to 30 files marked classified could have been accessed. A high‑level probe was ordered into the security breach, which was detected in December of the previous year.
News18 reports that a "notorious threat actor" claimed to have hyper-sensitive and classified data of multiple Indian forces, including the Indian Army, Indian Air Force, and Border Security Force, and put it up for sale on a forum. According to an unnamed official cited in the report, the actor claimed to have "data close to 40 GB containing 21,000 documents in more than 60 folders" and posted about 11 MB as a sample to attract buyers. Sources told News18 that the leaked documents include confidential annual reports, technical annual reports, layouts, and information on communication, deployment, and other sensitive architectures, and that the actor had created an account on a forum in June to sell various defence-related data for "thousands of dollars."
The Hindu reported that Algerian hackers successfully attacked a government server hosting websites of extremely sensitive organisations and defaced websites operated by DRDO and the Prime Minister’s Office. This is older background showing DRDO has been targeted before, but it does not address the 31 GB sale claim.
The breach-intelligence entry identifies Babuk as the threat actor and attributes the incident to DRDO, but it does not independently verify the claim. It is useful as a record of the alleged public leak, not as confirmation.
A video report on the Babuk Locker 2.0 cyberattack states that hackers allegedly stole highly confidential information related to VVIP security protocols and sensitive Ministry of Defence and DRDO files. The group claimed that on 10 March it had taken data from DRDO systems and, three days later on 13 March, it leaked a 753 MB sample on the dark web. Government sources quoted in the report said the stolen data were over four years old and had been accessed via an internet‑connected computer of a former IAS officer, rather than from a secure defence network.
According to this older report, hard disks stolen from DRDO’s Scientific Analysis Group and Institute for Systems Studies and Analyses in Delhi stored encryption codes, algorithms and data used to provide secure telecommunication links for different government agencies. Defence ministry sources claimed that no sensitive information was stolen, downplaying the theft, while security sources expressed concern that armed forces encryption may have been compromised. The case illustrates a pattern of Indian defence authorities sometimes minimising the sensitivity of stolen DRDO‑related data in public statements.
A Times of India report notes that the Indian defence establishment’s encrypted communication codes were stolen, with the theft having occurred nearly nine months before it was revealed. It states that the stolen codes had not been changed, potentially allowing foreign intelligence agencies to tap into supposedly secure communications among Indian defence and security officers. This illustrates historical vulnerabilities in Indian defence communications security but does not relate to a specific contemporary dark web sale of exfiltrated DRDO data.
ThePrint reports that the Central Bureau of Investigation (CBI) registered a case of espionage under the Official Secrets Act against defence journalist Vivek Raghuvanshi for allegedly leaking sensitive information on India’s defence projects and procurement to foreign intelligence agencies. While this case concerns leaking defence-related information, it involves human-source espionage rather than a cyber threat actor offering large volumes of exfiltrated DRDO and military data for sale online, and the article does not mention specific data volumes or a sale price.
What do you think of the claim?
Your challenge will appear immediately.
Challenge submitted!
For developers
This same pipeline is available via API.
Verify your AI's output programmatically.
/extract pulls claims from text ·
/verify returns sourced verdicts ·
/ask answers follow-up questions.
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
Source 2 (腾讯新闻) and Source 5 (CN-SEC) both independently report that on July 11, 2026, a threat actor posted on a dark-web forum offering 31 GB of allegedly exfiltrated sensitive data from DRDO's Research Centre Imarat and the Indian military for exactly USD 8,000, with sample files including missile seeker designs and UAV capability matrices — directly confirming every specific element of the claim. This is further corroborated by a well-documented pattern of DRDO-targeting cyber incidents across multiple high-authority sources (Sources 1, 3, 4, 6, 7, 8), establishing that such threat actor activity against DRDO is credible and consistent with prior behavior, making the claim well-supported and true.
The Proponent's argument commits a fallacy of division by conflating unverified dark-web forum advertisements reported in Source 2 and Source 5 with actual, confirmed data exfiltration from secure military networks. Furthermore, the Proponent relies on historical cyber incidents from 2025 (Source 1, Source 6, Source 18) to establish credibility, yet ignores that those very sources concluded the leaked files were actually outdated, non-sensitive documents taken from a former official's personal computer rather than a breach of DRDO systems.
Argument against
The claim of a 31 GB exfiltration of highly sensitive DRDO data is fundamentally misleading, as official DRDO representatives have explicitly denied any breach of their systems and confirmed the data does not belong to their organization (Source 1). Furthermore, independent investigations into similar dark-web leak claims reveal that the allegedly stolen files were actually outdated, non-sensitive documents accessed from an internet-connected computer of a former official rather than any secure defense network (Source 6, Source 18).
The Opponent conflates the 2025 Babuk Locker 2.0 incident — to which DRDO's denial and the 'outdated files' characterization in Sources 1, 6, and 18 pertain — with the distinct July 2026 dark-web listing documented in Sources 2 and 5, committing a category error that renders their rebuttal entirely inapplicable to the specific claim under examination. Moreover, the Opponent's reliance on official DRDO denials as dispositive proof ignores the well-documented institutional pattern, illustrated across Sources 9 and 19, of Indian defence authorities minimizing or denying breaches that are subsequently corroborated by independent evidence, meaning such denials carry limited evidentiary weight against two independently corroborating reports specifying the precise data volume and sale price.
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
The claim is logically supported by Source 2 and Source 5, which independently report that on July 11, 2026, a threat actor offered 31 GB of allegedly exfiltrated DRDO and Indian military data for USD 8,000. Because the claim is carefully qualified with 'allegedly' and refers specifically to the threat actor's offering rather than verifying the absolute authenticity of the breach, the evidence directly proves the claim's truthfulness.
Reviewer 2 — The Source Auditor
The claim specifically concerns a July 2026 dark-web listing offering 31 GB of allegedly exfiltrated DRDO and Indian military data for USD 8,000. The two most directly relevant sources for this specific claim are Source 2 (腾讯新闻, July 11, 2026, high authority) and Source 5 (CN-SEC, July 11, 2026, moderate authority), both of which report the same dark-web forum post with the same details — 31 GB, USD 8,000, DRDO/RCI and Indian military data, with sample files including missile seeker designs and UAV capability matrices. However, these two sources are not truly independent: they appear to be reporting on the same underlying dark-web forum post, meaning they are likely circular rather than independently verified. Source 2 (腾讯新闻) is a major Chinese news aggregator with high authority but no independent verification of the exfiltration itself. Source 5 (CN-SEC) is a Chinese cybersecurity blog of moderate authority. Neither source independently confirms that the data was actually exfiltrated from DRDO systems — they only confirm that a threat actor made this claim on a dark-web forum. The claim as stated says a threat actor 'is offering for sale' the data, which is a claim about the dark-web listing itself, not about whether the exfiltration was genuine. On that narrower reading, Sources 2 and 5 do confirm the listing exists with those specific parameters. The 2025 Babuk Locker 2.0 incident (Sources 1, 3, 4, 6, 7, 8, 18) is a distinct earlier event and does not directly confirm the July 2026 listing. DRDO's denials (Source 1) pertain to the 2025 incident. The claim's language — 'allegedly exfiltrated' — appropriately hedges on whether the data is genuine, making the claim essentially about the existence of the dark-web offer, which Sources 2 and 5 confirm. However, the evidence pool is thin: only two sources (both Chinese-language, both reporting the same forum post) confirm the specific July 2026 listing, with no independent Western or Indian media corroboration found. The confidence in the evidence pool is therefore moderate-low. The claim is mostly true as stated (a threat actor is offering the data for sale at that price), but the evidence base is narrow and potentially circular.
Reviewer 3 — The Precision Analyst
The claim's specific quantities and terms (31 GB, allegedly exfiltrated, highly sensitive, DRDO and Indian military, offered for USD 8,000) are directly matched by two separate reports describing a July 11, 2026 dark-web listing with those exact figures and characterization (Sources 2 and 5). Because the claim is explicitly framed as an offer of “allegedly exfiltrated” data (not a confirmed breach), earlier DRDO denials and unrelated 2025 Babuk reporting (Source 1) do not contradict the claim as worded, so the claim is mostly accurate at its stated strength.