HomeAnalysisWest Bengal Data Centre Attack Exposes Dangerous Cybersecurity Gaps

West Bengal Data Centre Attack Exposes Dangerous Cybersecurity Gaps

The reported cyberattack on West Bengal’s State Data Centre did more than disrupt government websites. It exposed how the security of a state’s digital administration depends on continuous monitoring, coordinated response, reliable backups and the ability to detect a breach before malware has time to move across connected systems.

According to a report by The Statesman, malware remained active on the data centre’s main server for five consecutive days, from September 9 to September 13. Government websites linked to several departments became non-functional after the attack, while backend operations for some services were also disrupted. A cyber-forensics team reportedly discovered the breach on the day after staff became aware of the problem.

The West Bengal State Data Centre is operated under the state Information Technology Department and controlled by West Bengal Electronics Industry Development Corporation Limited, or Webel. It stores digital records and supports websites and systems used by multiple departments, making it a critical piece of the state’s administrative infrastructure rather than a standalone technology facility.

The report says the affected departments include Public Works, Housing, Municipal Affairs and Urban Development, and the State Police. These departments perform functions that residents encounter directly, from public infrastructure and urban administration to policing and government information services. When a common data centre is disrupted, the effect can extend beyond a website outage: departments may lose access to online workflows, public information and backend systems needed for routine administration.

The reported incident also illustrates the concentration risk created when several public services depend on a shared digital platform. At least 50 virtual machines were active when the attack occurred, according to the report. Virtual machines allow multiple computing environments to run on shared physical infrastructure. Their presence does not by itself establish that all systems were compromised, but it indicates the scale of the environment that investigators had to examine and the number of possible access points within the centre.

The central uncertainty concerns the extent of the data compromise. The report says investigators fear that documents from four departments, including the Finance Department, may have been stolen or destroyed. It also says that none of the suspected stolen information had been recovered at the time of reporting. At the same time, experts said the Finance Department’s internal systems remained unaffected. These distinctions matter: a compromised shared repository, a disrupted public website and an unaffected departmental internal system are not necessarily the same event.

The information reportedly under scrutiny includes records related to earlier government schemes, birth and death registrations, micro and small-scale industries and government financial transactions. Data linked to ongoing welfare schemes, including the Annapurna Yojana, is also being examined. The report does not establish that all these records were stolen. It establishes that investigators are assessing whether they were accessed, copied, destroyed or otherwise affected.

That distinction is particularly important for beneficiaries. Government databases often bring together identity details, registration information and records of eligibility or assistance. The Statesman report says officials fear that beneficiary information could be misused for future fraud if it reaches cybercriminals. This is a stated risk arising from the reported incident, not confirmation that fraud has already taken place.

The reported five-day detection window is the most significant institutional question raised by the incident. The attack is said to have begun on September 9, while staff reportedly became aware of the problem only on the afternoon of September 13. Cyber-forensics personnel identified the breach the following day. The longer malware remains active, the more difficult it becomes to determine the initial entry point, isolate affected systems and establish whether information was viewed, copied or altered.

The report says Webel operates a Security Operations Centre intended to detect attempted breaches and trigger alerts. West Bengal also has a Cyber Security Incident Response Team, referred to as Cyber Yoddha, to handle such incidents. The existence of these mechanisms raises a practical question: whether alerts were generated and acted upon in time, whether monitoring covered the relevant systems, and whether the response chain functioned as designed. The supplied report does not provide an official explanation for the delay.

It also raises concerns about staffing. A significant portion of the personnel responsible for data-centre cybersecurity are reportedly contractual employees, prompting questions about training, continuity and operational accountability. These concerns should not be treated as proof of negligence. However, a high-dependency public data centre requires clearly assigned responsibilities, adequately trained staff and escalation procedures that remain effective across shifts and employment arrangements.

The incident also puts the state’s backup architecture under scrutiny. Critical data is typically maintained separately from live systems, but authorities are reportedly examining whether repeated attacks may have compromised those backups as well. A backup that is connected to the same environment, reachable through the same credentials or not regularly tested may not provide dependable recovery during a major breach. The report does not establish the design or condition of West Bengal’s backup systems, but the question has become central because the suspected stolen data had not been recovered.

The response described in the report included disconnecting servers belonging to various departments from the compromised server. That step can help limit further spread, but it cannot reverse access that may already have occurred. The report says the malware had become active within the system before the disconnection. This underlines the difference between containment and recovery: isolating systems can prevent additional damage, while determining what happened to the data requires forensic examination, logs, backups and verified system restoration.

The alleged attack is also not occurring in an entirely new institutional context. The report refers to earlier allegations in June 2025 involving the theft of birth and death certificate data, which the government did not acknowledge at the time. The current report does not establish whether that earlier allegation was connected to the latest incident. It does, however, show why repeated or unresolved concerns about public databases can weaken confidence in digital government even before the full technical facts are known.

For urban administration, the implications are direct. Housing, municipal affairs, public works and policing increasingly depend on digital records and online interfaces. These systems support planning, approvals, registrations, service delivery and public communication. A cyber incident can therefore become an administrative disruption, particularly when several departments rely on one shared data-centre architecture.

The episode also shows why cyber resilience is a governance issue rather than only an information-technology issue. Responsibility is distributed among the Information Technology Department, Webel, departmental system owners, security-monitoring teams, incident-response personnel and the officials who use the data. A failure at any point can affect the whole chain. Public accountability requires clarity on which systems were affected, what services were restored, whether personal information was accessed and what corrective measures are being taken.

At the time covered by the report, the investigation was continuing, the main server had not returned to normal operations and the government had not issued a public statement on the matter. The evidence therefore confirms a serious disruption and an active forensic investigation, while leaving the scale of confirmed data loss unresolved. The next important developments are an official account of the breach, a verified assessment of affected records, confirmation of backup integrity, restoration of departmental services and disclosure of measures to prevent a recurrence.


RELATED ARTICLES

Most Popular

Latest News