NIA raids 5 States over GOI websites cyber attacks

The National Investigation Agency (NIA) on Monday conducted searches at five locations across five states as part of its ongoing investigation into a major cyberterrorism case involving advanced DDoS attacks targeting key Indian Government websites.
The searches happened in Junnar (Pune district, Maharashtra), Nadiad (Kheda district, Gujarat), Ramagundam (Karimnagar district, Telangana), Gopalganj (Bihar), and Delhi. These actions are part of case RC-01/2025/NIA/AMD, known as the Cyber Terrorism Gujarat Case, which began on June 25, 2025.
According to the agency, the suspect tried to launch advanced DDoS attacks on 54 websites owned by various Indian Government entities. These attacks targeted important computer systems and the Critical Information Infrastructure (CII) as part of Operation Sindoor. Investigators believe the attackers wanted to threaten national security and unity, and to create public fear. Two suspects have already been arrested in this case.
The Anti-Terrorism Squad (ATS) in Gujarat first registered the case before the NIA took over. NIA officials say that after a detailed technical analysis, they identified additional suspects believed to have supported the main accused. These individuals are thought to have helped plan the attacks and to have improved the skills needed for DDoS operations.
After getting search warrants from a court, NIA teams raided the homes and other locations of the suspects early Monday morning. During the searches, investigators found several digital devices and documents related to hacking. They seized three laptops, five mobile phones, pen drives, and other digital storage devices. The suspects present at the sites were questioned to determine whether they were connected to the two people already arrested and whether they were involved in the cyberattacks.
Authorities emphasised that the operations followed all legal procedures. The seized items will undergo forensic examination to uncover additional links in the conspiracy and identify others who may have helped plan or support the attacks on key Government digital systems. This case highlights growing worries about cyber threats to national security. DDoS attacks like these aim to flood online systems with traffic, making websites unavailable and possibly disrupting important public services.
During a sensitive operational phase, the accused allegedly aimed to cause extensive disruption and damage. At a critical stage, the accused allegedly tried to cause major disruption and harm public confidence by attacking 54 Government websites. NIA teams are still analysing the digital evidence collected from the five locations. More arrests or legal action may follow, depending on what the forensic examination of the laptops, mobile phones, and other devices reveal.
Aspects of the conspiracy and to bring those liable to justice in accordance with the legal provisions concerned with cyber terrorism and threats to critical information infrastructure. The fact that the searches span multiple states shows that the alleged network had a nationwide presence.
The NIA’s actions are part of a broader effort to protect India’s digital assets from emerging cyber threats that could affect sovereignty and public order. As the investigation continues, authorities are expected to share more details about the technical methods used in the DDoS attacks and the level of support the accused received, whether from inside or outside the country.














