The standard assessment of state-sponsored cyber intrusion targeting the Indian system sees such actions as an attempt of sabotage of critical infrastructure – a compromised load dispatch center, an attacked port authority, a power grid being put offline. Applying this approach to the case of Digital Public Infrastructure of India is not only wrong, but misleading, as the problem appears on one level deeper than that. The ongoing events in the world of Aadhaar-linked systems, the Unified Payments Interface, CoWIN and other healthcare-related services and, more broadly speaking, the entire India Stack, do not represent separate instances of negligence in cyber hygiene of the resilient state. This is a subthreshold campaign that simply moved up from the infrastructure layer to the one of identity and transactions. India does not encounter a regular cyberconflict scenario at the level of this layer, but faces the same “grey zone” phenomenon, already known at the infrastructure layer – ambiguities, denials and subthreshold coercion – applied to the system that is supposed to become the crown achievement of India’s statecraft.
There are three main propositions underlying the argument that will be made here. First of all, the shift of the intrusion campaigns toward the Digital Public Infrastructure is a rational choice for a state-level actor and not just a coincidental extension of ordinary cybercrime, since the latter now allows to aggregate identity, biometric, financial and health data at the level unmatched by any other system. Secondly, India’s regulatory framework of DPI, which includes the Ministry of Electronics and Information Technology, sectoral regulators, CERT-In and the National Critical Information Infrastructure Protection Centre, has been developed with the consent and service provision as the primary objectives rather than the protection from state-level threat actors, hence creating the necessary gaps for grey zone strategy to exploit. And finally, the same hardware and lawfare advantages of China against the power sector and India’s trade policy apply equally well to the physical layer supporting DPI – the routers, cameras, biometric scanners and point-of-sale terminals that provide DPI’s physical interface with a billion of users.
The Architecture of Population-Scale Exposure
DPI is not CI with a new label – it is a separate order of target. A power station being compromised may degrade a whole region for several hours, but an identity layer being compromised will destroy the trust of people for a generation. The Aadhaar enrolled more than 1.3 billion residents, UPI processes over an excess of ten billion transactions a month, So, a structural failure of the system will spread to each service, bank and governmental scheme that has been created in connection with the platform. That is exactly what happened during the CoWIN episode demonstrated in June 2023, when a Telegram bot started returning the names, birthdates, Aadhaar IDs, passports and vaccination statuses of lakhs of Indian citizens due to some vulnerability in a separate system but not in CoWIN itself. The fact whether there was any breach in the CoWIN system is not important here. What matters is that the incident showed that even the government officials, sitting ministers and senior journalists became vulnerable because of the single interlinked point. It means that DPI’s major advantage – being interoperable on the single identity layer – also becomes a major drawback, as any adjacent system being compromised may lead to exposing the whole identity platform.
From Critical Infrastructure to Digital Public Infrastructure
This is no hypothetical escalation, either. China has proven itself capable and willing to penetrate India’s networks deep into critical sectors of strategic importance. Recorded Future’s Insikt Group documented in February 2021 a China-connected group dubbed RedEcho, operating via the infrastructure connected to the ShadowPad malware, known as part of a larger set of state-sponsored Chinese clusters, has launched an ongoing campaign of intrusions targeting ten entities from the power sector and two Indian ports, dating from early 2020 onwards, during the military stand-off in Pangong Tso. While Indian government representatives denied a clear connection between the intrusion campaign and the power outage incident in Mumbai in October 2020, the overall intrusion campaign against the power dispatch centres of India was not seriously challenged, and the event was later classified by the experts as a preparation for a future offensive, not an active use of capabilities at the moment. Pre-positioning strategic advantage does not end with the power grid. A network that collects the identities, the financial habits and the health statuses of over a billion people is a much more valuable target for pre-positioning than a load despatch centre, and the same Chinese hardware supply chain that already alarmed the defence and surveillance equipment procurement of India can be equally expected in the biometric scanners, point-of-sale devices and network infrastructure carrying the DPI traffic in the last mile.
The Legal Vacuum
While India has not been inactive in the area of data protection, its current tools were never created with such a threat model in mind. For instance, the Digital Personal Data Protection Act, 2023 regulates consent, data processing, and grievance redressal mechanisms among citizens, enterprises, and state bodies, yet, as a tool to prevent or detect the efforts by a foreign adversary to penetrate the identity layer for intelligence gathering and future use, the Act does not serve as one. CERT-In is still primarily a reactive organization which coordinates responses following a breach rather than conducting security-by-design audits before the implementation of the DPI stack elements. Furthermore, the National Critical Information Infrastructure Protection Centre while being legally empowered to protect banking, electricity generation and transmission, telecommunications, and healthcare sectors, fails to provide any guidance as to what to do with the DPI ecosystem, which includes interoperable platforms that interact with, yet are not contained within, those sectors. Lastly, India’s reliance on imported semiconductors, routers, and surveillance hardware creates a problem of supply chain security similar to the lack of legal instruments to address the problem of trade secret misappropriation. In the same way that the Twenty-Second Law Commission failed to find a dedicated Indian law covering the misappropriation of trade secrets, there is no legislative instrument requiring the DPI-related hardware vendors to undergo hardware assurance testing or make any disclosures about the presence of foreign components in their products.
Toward Threshold Recognition
Indeed, the exact characteristic makes the challenge a hard one to respond to in a conventional manner. While a leak of Telegram bot information, attempted intrusion into a load dispatch centre, or use of Chinese hardware in any sensitive procurement process does not, by itself, cross an escalatory boundary, their cumulative impact has been an ongoing degradation of India’s advantage, which was its creation of the interoperable identity and payment layer, which underlies its technological and economic sovereignty. For India, the challenge is not waiting for a DPI-specific event that is sufficiently impactful to warrant escalation since, by definition, grey zone strategy avoids ever having such an event occur. Instead, India must have a model wherein DPI is treated separately and as a category all on its own – apart from ordinary data protection and apart from conventional critical infrastructure. This means that there be constant audit by design of the DPI system ecosystem as a whole, as well as statutory application of CERT-In and NCIIPC jurisdiction to DPI-related systems, and treating the importation of foreign-made hardware as a matter of national security concern.

