LowII Cyber Warfare & Critical Infrastructure27 September 2026, Sunday
Pro-Pakistan group takes over Kerala government's administration website
The official website of the General Administration Department in India's Kerala state was taken over on the morning of 27 September and a Pakistani flag was placed on the page. A group calling itself Team Blackleets claimed the attack, and the hosting provider suspended the account.
According to reports by The Tribune and ThePrint on 27 September, the page carried a message praising Pakistan and claiming that many websites were being taken over every day. Attacks of this kind may be defacements, which change a site's appearance without accessing data. The General Administration Department said, however, that a cyber team was examining whether any data had leaked. As of 27 September, it could not be verified whether a data breach had occurred.
The department will report the incident to the Kerala Cyber Police and file a complaint; the site will be restored once it is secured, but no date was given. The state's main websites and e-government programmes are run by the Kerala State IT Mission. The attack came in the same weeks as border clashes between Pakistan and Afghanistan on 21–27 September, and as September reports of the Pakistan-linked APT36 group targeting Indian state institutions. No direct link between them could be verified.
Talay assessment
Bottom line
The incident looks more like nationalist hacktivist defacement than a state-backed operation, and it is confined to a single state website. Its significance lies in showing that state-level e-government infrastructure is still only protected at a basic level. If a data breach is confirmed, the weight of the incident will rise markedly.
Likely effects
- State e-government securityNegativeWeeks
The takeover of a state department's website in India may add pressure to review patching and hosting controls across state IT missions.
- India–Pakistan cyber tensionNegativeWeeks
Hacktivist groups tend to step up tit-for-tat defacements during periods of border and diplomatic tension; the 27 September incident fits this pattern.
Possibilities, ranked
- 1Closed as limited defacement70%
The review finds no data breach, and the site is restored within a few days.
Watch: The General Administration Department's review findings and the site coming back online
- 2Wave of tit-for-tat attacks25%
Hacktivist groups in India and Pakistan target other public websites on both sides.
Watch: New defacement reports on other state and ministry websites
- 3Data breach confirmed5%
The review reveals that personal or official data was stolen, and CERT-In steps in.
Watch: Statement from the Kerala Cyber Police or CERT-In
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- Official websites affected▼ 1
- Data breach disclosed▼ unverified