Website Hacking and Data Breach in India: Must a Business Notify Customers and Authorities

SW Solutions Ltd

Website Hacking and Data Breach in India: Must a Business Notify Customers and Authorities

A hacked website does not always mean that customer data has been stolen. Sometimes an attacker merely changes a webpage. In other instances, the same entry point exposes account credentials, payment records, identity documents, health information, or internal databases. 

That difference is important because an Indian business’s reporting duties depend on what happened, which data was affected, and whether sector-specific regulations apply.

The safest response is not to wait until every technical question has been answered. 

Instead, a business should contain the incident, preserve evidence, establish a reporting timeline, and obtain advice from cyber lawyers while the technical investigation continues.

Does Every Website Hack Need to Be Reported?

Certain cyber incidents must be reported to the Indian Computer Emergency Response Team, commonly called CERT-In. 

Its 2022 directions apply to service providers, intermediaries, data centres, body corporates, and other persons. 

Reportable incidents include: 

  • Unauthorised access
  • Attacks on servers and applications
  • Data breaches
  • Malicious code
  • Identity theft
  • Phishing

A report should be made to CERT-In within 6 hours of noticing or being informed of the incident. Initial information may be submitted first, followed by additional findings as the investigation develops. 

CERT-In’s own guidance recognises that complete information may not be available at the beginning. The directions also require that relevant system logs be securely retained in India for 180 days.

The practical question is whether the detected activity falls within a reportable category. Delaying solely because a forensic report is still incomplete may cause the 6-hour window to pass.

Should Affected Customers Be Told?

Under the Digital Personal Data Protection Act, 2023, a Data Fiduciary must give the Data Protection Board of India and every affected Data Principal an intimation of a personal data breach. 

The notified Digital Personal Data Protection Rules, 2025 describe customer-facing notices in plain language. This includes the nature and possible consequences of the breach, mitigation measures, safety steps, and contact details.

However, commencement is phased. 

The principal provisions covering security safeguards and personal data breach notification are scheduled to take effect 18 months after the Gazette notification dated 13 November 2025. 

As of August 2026, the DPDP customer-notification obligation is not yet the universal operative rule for every business. 

Existing contracts, privacy notices, consumer protection principles, and sectoral regulations may still require disclosure. Banks, insurers, payment operators, securities-market entities, and other regulated organisations face additional cybersecurity directions from their respective regulators. 

The applicable data protection law in India must therefore be read with the organisation’s licence conditions and contractual commitments.

When Customer Notification Becomes the Sensible Course

Even where a specific statutory notice is not yet triggered, a carefully prepared communication may reduce real harm. 

Customers may need to reset passwords, block cards, monitor bank accounts, revoke sessions, or watch for phishing messages. Silence can leave affected individuals unable to protect themselves.

A defensible decision generally considers:

  • Whether personal data was accessed, copied, altered, encrypted, or published
  • The sensitivity of the information, particularly passwords, financial details, health records, PAN or Aadhaar-linked data
  • The likelihood of identity theft, fraud, impersonation, discrimination, or account takeover
  • Whether the affected people can take meaningful protective action
  • Whether a regulator, contract, insurer, or law-enforcement authority requires notice

A rushed statement may disclose an unpatched vulnerability, wrongly minimise the event, or state facts that later prove inaccurate. Technical, legal, and communications teams should work from the same verified incident record, preferably with guidance from cyber lawyers.

What Indian Cases Reveal About Breach Response

In 2025, Generali Central Insurance approached the Bombay High Court after a ransomware incident allegedly exposed confidential customer information. The court granted interim protection and directed government authorities to block online channels connected with the stolen data. 

Reports also recorded that the insurer had notified CERT-In, IRDAI, and the cyber police. The episode shows why parallel technical, regulatory, criminal, and civil remedies may be required.

In May 2026, the Bombay High Court reportedly restrained a ransomware group from disclosing data allegedly taken from HDFC Asset Management Company. It directed authorities to disable channels associated with its distribution. 

The case illustrates the significance of urgent injunctions when stolen information is being threatened with publication. 

A separate 2026 petition by Vitraya Technologies concerned an alleged intrusion affecting medical and identity information. The Supreme Court issued a notice on a request for a central investigation. 

The allegations remain unproven, but the proceeding demonstrates the difficulty of investigating breaches involving sensitive records.

A Practical Response Sequence

The first hours should remain disciplined. The affected environment should be isolated without destroying logs. 

Passwords, keys, tokens, and privileged sessions should be reviewed. Investigators should identify the entry point, affected systems, data categories, and the likely period of unauthorised access.

The organisation should:

  1. Activate its incident-response and escalation process
  2. Preserve server, firewall, endpoint, cloud, and access logs
  3. Assess the CERT-In six-hour reporting requirement
  4. Check RBI, SEBI, IRDAI, contractual, and insurance obligations
  5. Document notification decisions and their factual basis
  6. Prepare accurate customer guidance where exposure creates a credible risk
  7. Consider a police complaint, injunction, or takedown request

Cyber security laws in India do not operate as a single checklist. They overlap across the Information Technology Act, CERT-In directions, the emerging DPDP framework, sectoral rules, contracts, and criminal law. 

Experienced cyber lawyers can help connect those duties without allowing legal review to delay urgent containment.

What It Comes Down To

A business facing website hacking should usually notify CERT-In when the event falls within a reportable category. This should happen within the prescribed 6-hour period. 

Customer notification is more fact-dependent today because the DPDP breach-notification provisions remain within their phased commencement period; sectoral rules and risk to individuals may still justify disclosure.

The strongest response begins with quick containment, preserved logs, and advice from cyber lawyers. It creates a record that can withstand regulatory scrutiny long after the website has been restored.

Sharing Is Caring:
Heat Caster - Best Quotes Having Attitude Status

Heat Caster

Welcome to Heat Caster, your number one source for all sorts of captions/quotes/status. We're dedicated to providing you the very best of Lines, with an emphasis on attitude and personality.

Contact Info