Skip to main content
Breaking News

Bengal Data Centre Hit by Major Cyberattack

A major cyberattack on the West Bengal State Data Centre (WBSDC) disrupted government portals and reportedly resulted in substantial data loss

2 min read0 views
Bengal Data Centre Hit by Major Cyberattack
Share

A major cyberattack on the West Bengal State Data Centre (WBSDC) disrupted government portals and reportedly resulted in substantial data loss, exposing potential weaknesses in the infrastructure supporting critical digital public services.

According to UNI and The Statesman, malware was active on State Data Centre servers for approximately five days, from September 9 to 13, 2026, before the scale of the incident became apparent.

Exactly how attackers initially penetrated the environment remains unclear. Public reports reviewed so far have not identified a confirmed vulnerability, compromised credential, phishing attack or other initial-access vector. An investigation is continuing.

Investigators reportedly found that at least 50 virtual machines were active during the incident, potentially providing access across multiple systems. Reports say data connected with government schemes, birth and death registrations, small-scale industries and financial transactions was being examined for possible compromise.

The consequences spread across public services. Websites associated with Public Works, Housing, Municipal Affairs and Urban Development and police services experienced problems, while Kolkata Municipal Corporation operations involving property taxes and birth and death registrations were also disrupted.

The incident is particularly significant because WBSDC describes itself as having extensive security controls, including IPS, malware protection, web application firewalls, sandboxing, four-layer application security and centralised SIEM monitoring.

Its infrastructure also includes automated incident notifications, application and database monitoring, dedicated backup networks and backup facilities for virtual machines. The state had additionally developed disaster-recovery infrastructure.

This raises the central question: how could malicious activity reportedly remain active for several days despite multiple security layers? That issue cannot be answered conclusively until forensic findings establish the intrusion path, lateral movement and detection failures.

Reports also indicate that recovery proved difficult and that significant portions of missing data could not initially be retrieved, prompting scrutiny of whether backup and disaster-recovery arrangements were sufficiently isolated from the affected environment.

The Bengal incident demonstrates that cybersecurity cannot depend simply on deploying multiple products. Critical government infrastructure requires continuous threat detection, network segmentation, privileged-access controls, immutable offline backups, behavioural monitoring and tested incident response—because the real measure of security is how quickly an intrusion is detected, contained and recovered from.