Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ... Listed by babuk2 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Indian Ministry of Defence and DRDO internal files were listed by the Babuk2 ransomware group on 10 March 2025 after being exfiltrated in a ransomware attack; the exact date of the intrusion has not been established. Individuals who may have had contact with the ministry or its research establishments should review their personal data and follow any official guidance that is issued.
When a ransomware group claims access to internal files from a defence research body, the practical stakes fall on people whose personal or professional details may sit inside those systems. Staff, contractors, researchers and anyone whose information appears in project records, correspondence or administrative databases can face lasting risks of identity misuse, targeted phishing or unwanted exposure of sensitive associations. Public detail on this incident remains limited, yet the claim itself is enough to warrant careful attention from anyone connected to India’s defence research community.
On 10 March 2025 the ransomware group known as babuk2 listed an entry describing access to Indian Ministry of Defence and military secret documents linked to the Defence Research and Development Organisation (DRDO). The listing characterises the material as internal files exfiltrated in a ransomware attack. No independent confirmation of the claim, no confirmed number of people affected and no detailed inventory of the files have been made public.
Breaking down the breach
According to the available record, babuk2 published a leak-site entry on 10 March 2025 under the headline “Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker.” The group asserts that it obtained internal files through a ransomware attack and refers to the operation as Babuk Locker 2.0. The number of people whose data may be involved is listed as unknown. The only data type named is “internal files exfiltrated in ransomware attack.” No further technical details—such as the initial access vector, the duration of the intrusion, the volume of data taken or any ransom demand—have been disclosed in the public summary. Because the listing originates solely from the threat actor, the claim remains unverified unless and until independent evidence appears.
Who is babuk2?
Babuk (sometimes styled Babuk Locker) is a ransomware operation that first gained public attention in 2021. The group has historically practised double extortion: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. Its operators have targeted organisations across multiple sectors and jurisdictions. After the group’s source code was allegedly leaked in mid-2021, various rebranded or derivative operations appeared; “babuk2” is one such moniker that has continued to appear on leak sites. Like other ransomware crews, babuk2 typically posts victim names and sample files on a dark-web site to pressure payment. Public reporting has not established any special relationship between babuk2 and Indian government networks beyond the single listing described here. Any statements the group makes about this particular victim should be treated as claims rather than What's Publicly Reported.
Who is Access to Indian Ministry of Defence and Military Secret (DRDO) documents By Babuk Locker ...?
The listing refers to documents associated with the Indian Ministry of Defence and, more specifically, the Defence Research and Development Organisation (DRDO). DRDO is the Indian government’s premier agency for military research and development; it designs and develops systems ranging from missiles and electronics to life-support and materials technologies. Organisations of this type routinely hold classified technical specifications, project plans, personnel records, contractor information, internal correspondence and administrative data. A breach claim involving such material is consequential because the information can touch national security, commercial partners and the private lives of scientists, engineers and support staff. The precise organisational unit or network that may have been affected has not been publicly identified beyond the group’s own wording.
What was likely exposed
The only data type explicitly named in the public record is “internal files exfiltrated in ransomware attack.” No inventory of file names, document classifications, personal data fields or volume has been released. Organisations engaged in defence research typically store technical reports, design documents, personnel files, email archives, financial records and contractor agreements. Whether any of those categories were among the files claimed by babuk2 remains unconfirmed. Readers should therefore treat any specific assertion about the contents as speculative until official sources provide further detail.
What's at stake
For individuals, the principal risks are identity theft, phishing campaigns that exploit knowledge of workplace relationships, and the possibility that personal contact details or employment history become public. Even if the bulk of the material is technical rather than personal, secondary documents often contain names, email addresses, phone numbers and organisational charts. For the organisation itself, the stakes include potential compromise of research programmes, loss of intellectual property, disruption of ongoing projects and the need to reassess network security. Because the number of people affected is unknown and the exact contents unconfirmed, the full scope of harm cannot yet be measured. Calm, methodical verification and protective steps remain the most useful responses.
Were you affected?
If you work or have worked with DRDO, the Indian Ministry of Defence, or related contractors, treat the claim as a prompt to review your own exposure rather than as proof that your data has been taken. Change passwords on any accounts that reuse credentials, enable multi-factor authentication where available, and monitor financial and email accounts for unusual activity. You can also run a free exposure scan of your email address against known breach data sets to check whether your information has already appeared in other incidents. Official confirmation from Indian authorities, if it comes, will provide clearer guidance; until then, basic digital hygiene is the practical next step.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Bangladesh Armed Forces (BangLadesh Army) Listed by babuk2 Ransomware GroupSaudi Arabian military and government internal center Listed by babuk2 Ransomware Groupdrdo.gov.in Listed by babuk2 Ransomware Groupnadra.gov.pk - NADRA official Of Pakistan Army & (Andhra Pradesh) Listed by babuk2 Ransomware GroupLatest breaches
Publicly posted by babuk2 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.