Cybersecurity is no longer just about protecting personal computers from viruses. Today, hackers are going after far bigger targets: hospitals, banks, power grids, and even smart city infrastructure. The digital transformation powering our urban centres has created new vulnerabilities that cybercriminals are eager to exploit. For smart cities to thrive, adopting the latest cybersecurity technologies is not optional-it is essential for survival.
Table of Contents
- The targets of attack are changing
- Healthcare and public services under threat
- Cyber threats are becoming more advanced
- AI-powered attacks on the rise
- The aftermath is grave
- Financial and operational costs
- Critical shift in the nature of cyber attacks
- Third-party risk as a systemic vulnerability
- Why adopting the latest technologies matters
- Zero trust architecture
- AI-powered threat detection
- Network segmentation and isolation
- Continuous monitoring and regular audits
- Building cyber resilience in smart cities
- Moving forward
The targets of attack are changing
Cybercriminals have fundamentally shifted their focus. Instead of targeting individual users for small financial gains, they now launch sophisticated attacks on critical infrastructure that can cripple entire systems and affect millions of people simultaneously.
A stark example of this shift was the 2021 Air India data breach. The attack compromised personal data of approximately 4.5 million passengers worldwide. The breach occurred through SITA, a third-party technology company that provides Passenger Service Systems to airlines globally. Hackers gained unauthorized access to SITA’s servers for about 22 days, stealing passengers’ names, credit card details, passport information, and frequent flyer data collected over nearly a decade.
This incident demonstrated how attackers are now targeting service providers that handle data for multiple organizations. SITA serves roughly 90% of the world’s airlines, meaning the breach affected not just Air India but also Singapore Airlines, Lufthansa, Cathay Pacific, and several other carriers. The interconnected nature of modern business infrastructure means a single vulnerability can cascade across dozens of organizations and millions of customers.
Healthcare and public services under threat
Hospitals, government portals, and municipal systems have become prime targets because they hold sensitive data and often run on outdated systems. Cyber incidents against India’s financial sector jumped from 53,000 in 2017 to approximately 16 million in 2023, according to a Reserve Bank of India report. This exponential increase reflects how attackers are systematically probing every digital system they can find.
Cyber threats are becoming more advanced
Modern cyberattacks are no longer the work of lone hackers in basements. They involve organized groups using sophisticated techniques, advanced tools, and persistent strategies that can evade traditional security measures.
In January 2021, threat intelligence firm CloudSEK discovered that personal data of 500,000 Indian police personnel was being sold on a database-sharing forum. The compromised information included full names, mobile numbers, email addresses, dates of birth, FIR records, and criminal histories. CloudSEK traced the data back to a police recruitment examination conducted in December 2019. The leaked database was validated by matching mobile numbers with candidates’ names, confirming its authenticity.
This breach was particularly alarming because it exposed law enforcement personnel to potential identity theft, targeted phishing campaigns, and social engineering attacks. Hackers could use this information to impersonate officers or conduct surveillance on police activities. The fact that such sensitive government data sat exposed for over a year before discovery highlights how advanced threats often operate undetected for extended periods.
AI-powered attacks on the rise
Attackers are now leveraging artificial intelligence to automate reconnaissance, craft convincing phishing messages, and identify system vulnerabilities faster than human defenders can patch them. The growing AI skills gap in organizations makes training in both AI and cybersecurity an absolute priority. AI places greater power in the hands of hackers, making sophisticated attacks accessible even to those who might otherwise lack technical capabilities.
The aftermath is grave
When critical infrastructure suffers a cyberattack, the consequences extend far beyond the immediate data loss. The interconnected nature of modern systems means a single breach can trigger cascading failures affecting financial operations, public safety, and citizen trust.
The State Bank of India’s “SBI Quick” vulnerability in January 2019 exposed the severity of such lapses. An unprotected server in a Mumbai data center was found storing millions of customer text messages in real time. The SBI Quick service allows customers to retrieve account information via SMS or missed calls-ideal for the millions who do not use smartphones. However, the backend system lacked password protection, exposing phone numbers, bank balances, recent transactions, and partial account numbers.
The server was sending approximately three million text messages daily, with archives going back two months. This data could have been used to profile high-value targets for fraud. As one security researcher noted, attackers could identify individuals with high account balances and target them specifically for scams or social engineering attacks. While SBI secured the server after the discovery and claimed no data was stolen, the incident exposed fundamental weaknesses in how India’s largest bank managed customer data.
Financial and operational costs
Studies estimate that a 24-hour smart city blackout could cost approximately โน1,200 crore and potentially affect 80 lives. These costs include emergency response, system restoration, business disruption, and long-term reputation damage. For organizations, the financial impact of data breaches includes regulatory fines, legal costs, customer compensation, and the massive expense of rebuilding compromised systems.
Critical shift in the nature of cyber attacks
Perhaps the most concerning trend is how attackers now exploit trusted third parties and supply chains to gain access to their actual targets. Rather than directly attacking well-defended primary systems, hackers target weaker links in the ecosystem.
The Upstox data breach of April 2021 exemplifies this strategy perfectly. Upstox, India’s second-largest stockbroking firm, discovered that hackers had compromised KYC data stored with a third-party data warehouse. The breach exposed information of approximately 2.5 million users, including names, email addresses, dates of birth, bank account details, and an estimated 56 million KYC documents containing Aadhaar cards, PAN details, passports, and signature images.
The attack was traced to a hacker group called ShinyHunters, which exploited a misconfigured Amazon Web Services (AWS) key. The compromised data was posted on the dark web, and the group reportedly demanded $1.2 million in ransom. This breach demonstrated how attackers can bypass an organization’s primary defences entirely by targeting their vendors and partners.
Third-party risk as a systemic vulnerability
The Air India breach highlighted that managing third-party risk is now critical as organizations increasingly rely on cloud providers and external vendors. Security experts emphasized that organizations constantly neglect to implement basic security controls, and these defects are not detected by auditors and regulators. The lack of adequate monitoring means security breaches go unnoticed for months.
Why adopting the latest technologies matters
Traditional security approaches cannot keep pace with evolving threats. Modern cybersecurity requires a multi-layered strategy incorporating the latest technologies and frameworks.
Zero trust architecture
The zero trust model assumes no user or device should be automatically trusted, even inside the network. Every access request must be verified, authenticated, and authorized. Smart cities implementing zero trust can contain breaches more effectively by preventing lateral movement-the ability of attackers to move from one compromised system to others across the network.
AI-powered threat detection
Artificial intelligence can analyze vast amounts of network traffic and system logs to identify anomalies that human analysts might miss. Some Indian cities are now using AI-based systems that can block over 99% of threats in real time. These systems learn normal network behaviour and flag deviations that might indicate an attack in progress.
Network segmentation and isolation
Compartmentalizing endpoints ensures that each device remains autonomous within the network. If attackers compromise one system, proper segmentation prevents them from accessing other critical infrastructure. This approach can stop the spread of malware and limit attacker mobility within the network.
Continuous monitoring and regular audits
The Indian government has established CERT-In as the national agency for responding to cybersecurity incidents, along with the National Cyber Coordination Centre for detecting threats and the National Critical Information Infrastructure Protection Centre for protecting critical systems. Organizations must integrate with these frameworks while conducting their own regular vulnerability assessments and penetration testing.
Building cyber resilience in smart cities
Smart cities face unique challenges because they integrate thousands of IoT devices, sensors, and control systems. In 2024, over 96% of discovered vulnerabilities in smart city systems were traced to web applications-the very dashboards and portals that manage traffic, utilities, and citizen services. Critical vulnerabilities surged by more than 83% compared to 2023.
For smart cities to remain secure, cybersecurity must be embedded from the design phase rather than added as an afterthought. CERT-In’s analysis of 20 Indian smart cities revealed that trojan malware remains the dominant threat across western, central, and northern regions. Each component of smart city infrastructure-from IoT sensors at the edge to centralized data centres-requires specific security controls tailored to its role.
Privacy-by-design principles, as mandated by the Digital Personal Data Protection Act, ensure that data protection measures are integrated into systems from the beginning. This approach reduces breach probability and builds the public trust necessary for citizens to embrace smart city technologies.
Moving forward
The incidents involving Air India, SBI, Upstox, and police personnel data are not isolated failures-they represent a pattern that will intensify as digital systems become more interconnected. Cybercriminals are becoming more sophisticated, better funded, and increasingly patient in executing their attacks.
Adopting the latest cybersecurity technologies is not about chasing trends. It is about recognizing that legacy systems and traditional approaches are fundamentally inadequate against modern threats. Organizations managing critical infrastructure and smart city systems must prioritize continuous security upgrades, vendor risk management, employee training, and incident response planning.
The cost of prevention will always be lower than the cost of recovery. As cities become smarter, they must also become significantly more secure.
What do you think? How should governments balance the convenience of interconnected smart city services with the security risks they introduce? Are citizens adequately informed about how their data is protected-or exposed-in these digital urban ecosystems?
References
- https://techcrunch.com/2021/05/23/air-india-passenger-data-breach-reveals-sita-hack-worse-than-first-thought/
- https://www.darkreading.com/cyber-risk/india-s-critical-infrastructure-suffers-spike-in-cyberattacks
- https://www.cloudsek.com/threatintelligence/police-exam-database-exposes-500k-indian-citizens-pii
- https://www.networkerschamp.com/news/the-future-of-cybersecurity-in-india/
- https://techcrunch.com/2019/01/30/state-bank-india-data-leak/
- https://www.businesstoday.in/technology/news/story/upstox-alerts-users-of-data-breach-assures-safety-of-funds-securities-293306-2021-04-12
- https://hackread.com/shinyhunters-broker-firm-upstox-database-leak/
- https://www.csoonline.com/article/570797/air-india-data-breach-highlights-concerns-around-third-party-risk-and-supply-chain-security.html
- https://cxotoday.com/security/why-smart-cities-are-sitting-ducks-for-cyber-criminals/
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2116341
- https://www.getastra.com/blog/security-audit/cybersecurity-best-practices-for-smart-cities/
- https://www.cert-in.org.in/PDF/Guidelines_for_Smart_City_Infrastructure.pdf
Leave a Reply